A new Android banking trojan identified as Rokarolla is actively targeting 217 banking and cryptocurrency applications, leveraging an extensive arsenal of 137 distinct commands to achieve near-complete administrative control over compromised devices. The malware, documented by mobile security firm Zimperium, represents a significant escalation in the threat landscape for mobile financial fraud, combining sophisticated evasion techniques with broad data-theft capabilities.
Rokarolla Distribution and Installation Tactics
Rokarolla is distributed through malicious websites that impersonate legitimate download pages for popular applications such as Google Chrome and TikTok. During the installation process, the malware operates as a dropper, presenting users with a convincing impersonation of Google Play Protect, Android’s built-in anti-malware system. Victims are offered the option to install Chrome or TikTok, but the downloaded package includes the Rokarolla payload. Upon execution, the trojan immediately requests Accessibility service permissions, as well as access to notifications, SMS messages, and call logs. These permissions are the foundation of its ability to operate covertly and intercept sensitive data.
Command-and-Control Communication and Device Profiling
Once installed, Rokarolla establishes communication with its command-and-control (C2) server by transmitting a detailed device profile. This profile includes the phone model, installed Android version, locale settings, display characteristics, battery level, storage capacity, and available RAM. According to Zimperium, this information is used to generate a unique identifier for each victim, enabling targeted and persistent control over individual compromised devices.
Financial Data Theft Through Fake Login Overlays
The primary objective of Rokarolla is the theft of financial information. The malware maintains a list of 217 targeted banking and cryptocurrency applications. When the victim opens any matching app on the infected device, Rokarolla displays a fake login overlay designed to capture login credentials, credit card numbers, and other sensitive financial data. This overlay technique is also employed to capture the device’s lock-screen PIN or pattern, and to operate the phone even when the screen is locked. Fake installation screens are displayed to hide malicious activity and block user interaction when necessary.
Key Capabilities and Data-Theft Commands
The 137 commands available to Rokarolla operators enable a wide range of malicious actions. Key data-theft capabilities include stealing SMS messages, extracting contact information and WhatsApp contacts, capturing keystrokes through keylogging, recording on-screen content via UI logging, copying and manipulating clipboard contents, blocking incoming calls and bank fraud alerts, and periodically taking screenshots that are uploaded with timestamps. This combination of capabilities gives attackers near-complete administrative control over the device, facilitating advanced financial fraud.
Evasion and Persistence Techniques
Rokarolla employs multiple evasion tactics to avoid detection and maintain persistence. These include disabling Google Play Protect, hiding the application icon from the app drawer, silencing audio and vibration feedback, and keeping the device screen awake indefinitely. These measures significantly reduce the likelihood that a victim will notice the malware’s presence or activity.
What Is the Rokarolla Android Trojan?
Rokarolla is a newly discovered Android banking trojan that targets 217 financial and cryptocurrency applications using 137 predefined commands. It spreads through fake download pages for popular apps like Google Chrome and TikTok, and uses fake overlays to steal login credentials, credit card data, and other sensitive information. It also captures lock-screen credentials, logs keystrokes, and can take full administrative control of an infected device.
What Affected Users Should Do Now
Zimperium has not found Rokarolla on the official Google Play Store. Users are strongly advised to avoid downloading APK files from any source outside the official Google Play Store unless the publisher is explicitly trusted. Exercise extreme caution when granting Accessibility permissions, as this feature is frequently abused by Android malware to bypass standard security protections and obtain elevated capabilities, including interacting with the user interface and approving system prompts. For users who suspect their device may be compromised, the immediate steps are to run a full scan using a reputable mobile security solution with real-time threat detection capabilities, review and revoke any suspicious Accessibility permissions, and monitor banking and cryptocurrency accounts for unauthorized activity. Enabling two-factor authentication on all financial accounts provides an additional critical layer of protection against credential theft.