New Rokarolla Android malware targets 217 banking, crypto apps
Security researchers have uncovered Rokarolla, a new Android banking trojan that targets 217 banking and cryptocurrency apps. Distributed via fake Chrome or TikTok installers, it acts as a dropper and masquerades as Google Play Protect to gain elevated privileges. Once on a device, Rokarolla uses overlays to steal login credentials and financial data, captures keystrokes, SMS, contacts, and screenshots, and can even keep the device awake or disable protections. Zimperium’s report maps 137 commands and a GitHub repo detailing the botnet’s capabilities, marking Rokarolla as capable of near-complete administrative control.
.jpg)
New Rokarolla Android Malware Targets 217 Banking and Crypto Apps
OverviewA newly identified Android banking trojan, named Rokarolla, is actively targeting a broad slate of financial and cryptocurrency applications. Researchers describe Rokarolla as capable of exerting near-complete administrative control over an infected device through an extensive set of 137 commands. The campaign emphasizes financial data theft, with the malware leveraging overlays, credential harvesting, and device-level control to operate covertly and persistently.
Spreading method and initial compromise
- Rokarolla is distributed via malicious websites that purport to offer legitimate apps such as Google Chrome or TikTok.
- The installer acts as a dropper and impersonates Google Play Protect, tricking users into installing the compromised versions of Chrome or TikTok.
- Once installed, the malware seeks elevated access by requesting Accessibility service permissions, along with access to notifications, SMS, and calls.
- The infection process is designed to give attackers broad visibility into the device’s state and to enable stealthy operation even when the device is in use or locked.
Installation flow and device enrollment
- The malware begins by presenting itself as a legitimate system protection feature, encouraging users to proceed with the installation of seemingly benign apps.
- After activation, Rokarolla establishes a foothold by acquiring critical permissions that enable interaction with the user interface and system prompts.
- A device profile is sent to the command-and-control (C2) server to initialize the campaign. The profile includes hardware and software details such as phone model, Android version, locale, display characteristics, battery level, storage, and RAM.
- This information is used to generate a unique identifier for each infected device, facilitating individualized tracking within the Rokarolla operation.
Targeting and payload delivery
- Rokarolla maintains a list of 217 targeted applications, spanning banking and cryptocurrency services.
- For any matched app on the device, the malware downloads a phishing payload tailored to that app’s ecosystem.
- When a user opens a targeted app, Rokarolla presents a fake login overlay designed to capture credentials, payment details, and related financial information.
Financial data theft and overlay usage
- The primary objective is theft of financial information, achieved by overlaying legitimate-seeming login screens on top of real apps.
- Overlays are also used to capture lock-screen credentials (PIN or pattern) and to control the device even when it appears locked.
- Additional overlays simulate installation screens and other UI prompts to mislead users and maintain control over interactions.
Evasion, concealment, and persistence
- Rokarolla employs several evasion tactics to remain hidden and operational:
- Disables Google Play Protect to reduce automatic removal risk.
- Hides its application icon from the app drawer to avoid easy discovery.
- Silences audio and vibration and can keep the screen awake to ensure continued visibility of overlays.
- The attackers rely on overlays not only for credential theft but also for concealing malicious activity and steering user actions as needed.
Command-and-control and capabilities
- Zimperium researchers uncovered a GitHub repository listing 137 commands that Rokarolla can execute, enabling a wide range of data exfiltration and device manipulation.
- Notable data-theft capabilities include:
- Stealing SMS messages
- Extracting contact information and WhatsApp contacts
- Capturing keystrokes
- Recording on-screen content via UI logging
- Copying and manipulating clipboard contents
- Blocking incoming calls and bank fraud alerts
- Periodically taking screenshots with timestamps and uploading them
Impact and operational scope
- The combination of device control, targeted phishing payloads, and extensive data-collection commands enables operators to conduct sophisticated financial fraud with a high degree of stealth.
- The approach shows a deliberate emphasis on near-total administrative control over compromised devices, enabling persistent access to sensitive financial data and user interactions.
Security observations and context
- The malware reportedly has not been found on Google Play, reinforcing the need to avoid APKs from untrusted sources and to scrutinize the publishers of apps obtained outside official stores.
- Access Permissions: The use of Accessibility services and other elevated permissions is central to Rokarolla’s ability to interact with the user interface and system prompts, highlighting a key vector for abuse in Android environments.
- Defense-relevant indicators include the presence of fake login overlays, unusual permission requests, and the pairing of legitimate-looking app installations with malicious payloads.
Notes on the campaign and attribution
- The findings originate from mobile security researchers who analyzed the Rokarolla family and its command set, along with observed behavior during infections and payload delivery.
- The operation emphasizes a standardized set of steps: initial deception to install, device profiling, targeted payload selection, overlay-based credential theft, and covert data exfiltration backed by a large suite of commands.
Observations for defenders and analysts
- Comprehensive app vetting and user education remain critical, particularly around advertisements and dropper-style installers that bundle legitimate-looking apps with malicious payloads.
- Monitoring for overlay use, excessive permission requests, and abnormal device behaviors can aid in early detection of similar banking Trojans.
- The breadth of targeted apps suggests a need for threat intelligence that tracks 217 identified financial and crypto services to anticipate potential phishing payloads.


