A new Android Trojan targets 217 banking apps: steals PINs, SMS codes, and crypto wallets

Cybersecurity researchers from the zLabs team of Zimperium have identified a new and sophisticated threat: a banking Trojan for Android devices capable of taking near-total control of infected smartphones.

Nicknamed Rokarolla, after the criminals’ command-and-control infrastructure, this malware targets as many as 217 financial applications, including traditional banking services and cryptocurrency management platforms.

With an arsenal of 137 remotely executable commands, the malicious code surpasses in complexity even recent threats such as the HOOK trojan, which stopped at 107 instructions.

Rokarolla is the new Trojan that drains your bank account

Malware
Credits: Canva

Rokarolla spreads through malicious websites that pose as legitimate versions of very popular apps, such as TikTok or the Google Chrome browser.

The first component the victim downloads is an installer masquerading as Google Play Protect.

Taking advantage of this clever disguise, the malware tricks the user into granting the operating system’s Accessibility permissions. Once installed and operational, the Trojan’s first step is precisely to disable the real protection of Google Play Protect, depriving the device of its main built-in automatic defense.

The financial theft mechanism orchestrated by the Rokarolla developers relies mainly on the use of overlay screens. The trojan downloads from its server an updated list of targets and, for each banking app or digital wallet detected as active on the smartphone, stores in a local database a fake login page in HTML format.

The moment the user opens the legitimate banking app, the malware instantly overlays the fake page. Any information entered on this screen, including credit card details and login credentials, is immediately captured and transmitted to the attackers.

A second fake screen is used to perfectly replicate the native Android lock screen. This ploy allows criminals to record the PIN, the unlock sequence, or the device password, giving remote operators the ability to send commands and navigate the system even when the smartphone is physically locked by the owner.

Total surveillance and manipulation of transactions

The malware’s spying capabilities are extensive. It acts as a keylogger to record every keystroke on the on-screen keyboard and systematically reads all incoming notifications.

Moreover, it has full access to SMS messages: it can read incoming messages and send new ones without any manual intervention. This function is crucial for intercepting one-time codes banks send to authorize payments or new logins.

Becoming the default handler for messages and calls, the Trojan is even able to block incoming calls, effectively preventing the bank’s anti-fraud alerts from reaching the victim.

A equally grave danger concerns those handling cryptocurrency assets. The malware silently analyzes and rewrites the OS clipboard. If the user copies the address of a digital wallet to make a payment, Rokarolla replaces it in a fraction of a second with a destination address controlled by the criminals, diverting funds irreversibly to illicit accounts.

To visually monitor the victim’s behavior without arousing suspicion, the trojan avoids traditional video transmission methods that would show a recording icon in the status bar. Instead, it uses Accessibility permissions to take continuous screenshots, compressing them into PNG format and sending them to the servers one frame at a time, operating in absolute silence.

Resilient Architecture and Security Measures

The network infrastructure supporting Rokarolla is designed to withstand attempts to dismantle by authorities.

The malware keeps multiple emergency domains active for command-and-control operations and can receive new ones in real time. Consequently, taking down a single server is totally ineffective at stopping the fraudulent campaign.

Although Zimperium has not yet formally attributed the attack to a specific group of cybercriminals, the technical setup shows a notable level of sophistication.

Being an active infection rather than an intrinsic vulnerability of the underlying software, there is no automatic patch able to resolve the problem.

Protection rests exclusively on the users’ preventive discipline: install applications only from the official Google Play Store, constantly verify that Play Protect is enabled, and consider any unexpected request for Accessibility services access as a sign of compromise, because it is exactly that authorization that triggers and sustains the entire attack cycle.