Rokarolla Android Trojan Hits 217 Banking and Crypto Apps
Researchers at Zimperium's zLabs catalogued 137 remote commands in the new malware, including PIN capture and clipboard hijacking against crypto wallets.

A new Android banking trojan called Rokarolla targets 217 banking and cryptocurrency applications, according to a technical writeup from Zimperium's zLabs. The malware ships with 137 remote commands, a notable expansion of the operator toolkit seen in this family of threats.
The command set is what makes this one worth a closer read.
Rokarolla captures lock-screen PINs, intercepts and sends SMS messages, and rewrites clipboard contents to redirect cryptocurrency transfers to attacker-controlled addresses. It also attempts to disable Google Play Protect, removing one of the default guardrails on the device.
That last capability matters for the regulatory conversation. Google Play Protect is the on-device scanner that the company cites in its annual transparency reporting as a primary defense against sideloaded malware. A trojan that switches it off pre-empts that control entirely.
The targeting list of 217 apps spans both traditional banking institutions and crypto wallet software. zLabs has not, at the time of writing, published the full target inventory or indicators of compromise in a public feed, though the firm typically releases hashes and C2 domains alongside its full report.
For enterprises with bring-your-own-device policies, the clipboard-rewrite behavior is the one to flag to treasury and finance teams. Wallet addresses copied from a legitimate exchange interface can be silently swapped before the user hits paste. The user sees what they expect to see until the transaction confirms on-chain.
There is no formal regulatory action tied to Rokarolla yet. But the malware lands in an environment where mobile threats are increasingly drawing supervisory attention. The FFIEC's authentication guidance, last meaningfully updated in 2021, treats SMS-based one-time passcodes as a weak factor precisely because of trojans of this class. The EU's DORA framework, which took effect 17 January 2025, requires in-scope financial entities to maintain ICT risk controls covering customer-facing channels — mobile banking included.
Firms regulated under the SEC's cyber disclosure rule (17 CFR §229.106, final, effective 18 December 2023) should note that a confirmed Rokarolla compromise affecting customer accounts could meet the materiality threshold for an Item 1.05 8-K filing, depending on scale and financial impact. The determination is fact-specific.
For now, the practical guidance is narrow. Do not sideload Android apps from outside Google Play. Verify Play Protect is enabled at Settings > Google > All services > Play Protect. Treat any prompt to grant Accessibility Services on a banking-adjacent device as hostile until proven otherwise.
zLabs has not attributed the trojan to a named actor. CVE assignment is not applicable here — this is malware, not a platform vulnerability — and Google's response, if any, will likely surface through Play Protect signature updates rather than a formal advisory.



