Rokarolla Android Trojan Hits 217 Banking and Crypto Apps
Researchers at Zimperium's zLabs catalogued 137 remote commands in the new malware, including PIN capture and clipboard hijacking that silently redirects crypto payments.

Key points
- Rokarolla targets 217 banking and cryptocurrency apps with 137 remote commands
- It captures lock-screen PINs, reads and sends SMS, and rewrites clipboard contents to redirect crypto transfers
- The malware disables Google Play Protect, removing the default on-device scanner
- No actor attribution or CVE assignment has been made
- Enterprises with BYOD policies should flag the clipboard-rewrite behavior to treasury teams immediately
A new Android banking trojan called Rokarolla targets 217 banking and cryptocurrency applications, according to a technical writeup from Zimperium's zLabs. It ships with 137 remote commands, giving an operator near-total control of an infected device.
What can Rokarolla actually do?
The command set is what earns this one a close read. Rokarolla captures lock-screen PINs, reads and sends SMS messages, and rewrites clipboard contents so that a cryptocurrency address copied from a legitimate exchange is silently swapped before the user hits paste. The user sees what they expect to see until the transaction confirms on-chain. It also disables Google Play Protect, the on-device scanner Google cites as a primary defense against sideloaded malware, pre-empting that control entirely.
The targeting list spans both traditional banking institutions and crypto wallet software. ZLabs hadn't published a full target inventory or indicators of compromise in a public feed at the time of writing, though the firm typically releases hashes and command-and-control domains alongside its full report.
Should you worry about this at work?
For enterprises running bring-your-own-device policies, the clipboard-rewrite behavior is the one to flag to treasury and finance teams first. Wallet addresses don't look wrong until a transaction confirms.
We covered the BTMOB Android banking trojan in May, and the pattern here is consistent: commodity trojans are getting broader target lists and more granular command sets without attracting proportionately more regulatory attention. The FFIEC's authentication guidance treats SMS-based one-time passcodes as a weak factor precisely because of trojans in this class, and the EU's digital-resilience framework for financial entities, which requires ICT risk controls covering customer-facing mobile channels, is now in force. Firms subject to the SEC's cyber disclosure rule should also note that a confirmed Rokarolla compromise affecting customer accounts could meet the materiality threshold for an 8-K filing, depending on scale and impact. That determination's fact-specific.
What should you do right now?
Don't sideload Android apps from outside Google Play. Confirm Play Protect is enabled at Settings > Google > All services > Play Protect. Treat any prompt to grant Accessibility Services on a banking-adjacent device as hostile until proven otherwise.
ZLabs hasn't attributed the trojan to a named actor. CVE assignment doesn't apply here since this is malware, not a platform vulnerability. Google's response, if any, will most likely surface through Play Protect signature updates rather than a formal advisory.



