
ROKAROLLA, a newly identified Android banking trojan, has been observed stealing cryptocurrency wallets and online banking credentials from more than two hundred applications according to Zimperium researchers. The malware spreads through malicious websites that mimic popular apps such as TikTok and Google Chrome, tricking users into installing a dropper that poses as Google Play Protect. Once installed, it requests broad permissions and begins a full device takeover. This campaign was first seen in mid‑June 2026 and remained active through the end of the month.
After gaining access to Android’s Accessibility Services, Rokarolla hides its launcher icon and connects to a remote command‑and‑control server as detailed in a SecurityOnline analysis. It then downloads counterfeit HTML pages that overlay legitimate banking and crypto apps, capturing usernames, passwords and one‑time codes. The trojan also disables Google Play Protect to avoid detection and can send SMS messages from the victim’s number to spread further or to interfere with authentication flows.
Additional capabilities include a keylogger that records every tap, silent screenshot capture, and clipboard manipulation that replaces copied wallet addresses with attacker‑controlled strings per a SecurityWeek report. Rokarolla can block incoming calls, mute notifications and even hijack ongoing voice calls to prevent users from noticing fraudulent activity. The malware exposes over one hundred thirty distinct commands that allow remote operators to exfiltrate data, install further payloads or wipe device logs.
Zimperium’s telemetry shows the trojan was active from 16 June 2026 to 25 June 2026, with victims across several regions as noted by Malwarebytes. No CVE identifier has been assigned to the underlying vulnerabilities, and no specific threat‑actor group has been publicly linked to the campaign. The reliance on social engineering rather than a software flaw means the threat persists as long as users install apps from unverified sources.
The emergence of Rokarolla highlights a broader trend where mobile banking trojans combine classic credential theft with extensive device surveillance according to SecurityAffairs. By masquerading as popular social‑media or browser apps, the dropper bypasses user suspicion and gains the deep access needed for overlay attacks. Researchers note that such tactics are becoming more common as attackers seek to defeat built‑in Android protections.
Defenders should advise users to download applications only from official stores and to verify the developer name before installing any app that requests Accessibility or SMS permissions as suggested by DarkReading. Enabling Google Play Protect and keeping the operating system up to date reduces the chance of successful installation. Users who notice unusual SMS sent from their device or unexpected call blocking should immediately revoke suspect app privileges and run a mobile security scan.
Organizations can further reduce risk by enforcing app‑whitelisting policies on corporate‑owned devices and by deploying mobile threat‑defense solutions that monitor for overlay behavior and anomalous network traffic per InfoSecurity Magazine. Educating employees about the dangers of sideloading and about verifying app authenticity helps prevent the initial compromise. Continuous monitoring of outbound connections to known malicious domains can flag a Rokarolla infection before data is exfiltrated.
Finally, maintaining regular backups of important data and using strong, unique passwords for banking and crypto services limits the impact if credentials are captured. Promptly reporting suspicious apps to the relevant app store and to security vendors helps improve global defenses against evolving mobile threats as advised by Zimperium.