VYPR
researchPublished Jun 16, 2026· Updated Jun 29, 2026· 10 sources

Rokarolla Android Banking Trojan Blends Fraud with Full Device Surveillance

A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency apps with overlay attacks and SMS interception, while also capturing screen content and recording audio for long-term victim monitoring.

A newly discovered Android banking trojan has been observed going beyond draining accounts, seizing near-total control of a phone and cutting victims off from their banks so fraud can run undetected.

Named Rokarolla after its command-and-control (C2) servers, the malware was detailed by zLabs, the research arm of mobile security firm Zimperium, which found it targeting 217 banking and cryptocurrency apps through a toolkit of 137 commands. It spreads through malicious sites that masquerade as TikTok or Google Chrome, using a dropper that poses as Google Play Protect to slip a second-stage payload past Android's defenses and onto the device.

"The Rokarolla trojan marks a shift from data theft to victim isolation," explained Jason Soroko, senior fellow at certificate-management firm Sectigo, who described Rokarolla turning the phone into a weapon against its owner.

To keep that grip, Rokarolla makes itself the device's default handler for calls and texts. It can block incoming calls and read or send SMS messages, letting it swallow the one-time codes and fraud alerts a bank would normally use to flag a suspect transfer. It also mutes the phone's audio and vibration to hide alert tones, hides its own icon from the app drawer and forces the screen to stay awake so its hidden activity is never interrupted.

The theft leans on Accessibility Services, the Android feature for assistive apps, which Rokarolla abuses to read the screen and drive the interface. From there it harvests banking and crypto logins captured by fake overlay screens, lock screen PINs, patterns and passwords, keystrokes and on-screen text, SMS messages including bank one-time codes, and even WhatsApp contacts scraped from the display.

When a victim opens a targeted app, the malware drops a convincing fake login page fetched from its server over the real one. It can also rewrite the clipboard on the fly, swapping in an attacker's cryptocurrency wallet address when the victim copies their own. For surveillance, rather than streaming the screen live, Rokarolla quietly takes timestamped screenshots and exfiltrates them one by one. It also tries to disable Google Play Protect to keep itself hidden.

The campaign coincides with a substantial increase in mobile threats. Randolph Barr, CISO at API security firm Cequence Security, noted, "Android continues to face banking trojans and data-leaking SDKs," citing tens of millions of mobile malware incidents blocked in 2024 alone.

Rokarolla underscores the growing sophistication of mobile malware that combines credential theft, SMS interception, and device surveillance into a single attack. The dual threat — financial fraud and privacy invasion — poses significant risks to users in Europe and Latin America, where the campaign appears concentrated.

The Hacker News report adds new technical detail: the trojan not only launches overlay attacks and intercepts SMS but also actively disables Google Play Protect to evade defenses, and it hijacks clipboard data to redirect cryptocurrency payments to attacker-controlled wallets. The 137 remote commands give operators near-total device control, including the ability to capture lock-screen PINs in real time.

Zimperium's follow-up report on Rokarolla reveals the trojan now uses a sophisticated suite of 137 commands to achieve full device control and persistence, going beyond the earlier described overlay and SMS interception. The updated malware deploys fake TikTok and Chrome download sites, actively disables Google Play Protect, suppresses all device audio and vibrations to hide fraud activity, and employs dynamic C2 updates with multiple fallback domains to resist takedowns. The extensive command set includes harvesting lock screen credentials, keylogging, blocking incoming calls, and deploying fraudulent screen overlays that render the device nearly unusable by the owner while intercepting bank alerts.

Zimperium's full technical report, released today, reveals that Rokarolla communicates with its C2 server by sending a detailed device profile — including phone model, Android version, locale, and battery level — to generate a unique victim identifier. The malware is distributed via malicious websites posing as Google Chrome or TikTok download pages, and during installation it impersonates Google Play Protect to trick users into granting Accessibility permissions. Zimperium has published a GitHub repository listing all 137 commands available to Rokarolla operators, which include stealing SMS messages, extracting WhatsApp contacts, capturing keystrokes, and blocking incoming calls and bank fraud alerts.

Zimperium's zLabs detailed that Rokarolla is distributed via malicious websites, primarily infocontablidades.it.com, tricking users into side-loading fake versions of TikTok and Google Chrome. The malware can deactivate Google Play Protect, block incoming calls from financial platforms, and use fake screen overlays with silenced audio to conceal its activity. Researchers emphasized that Rokarolla's ability to intercept SMS authentication codes and block calls disrupts standard fraud prevention measures, cutting off users from reporting suspicious activity.

A fresh Zimperium analysis, shared with Cyber Security News, deepens the technical picture of the campaign: Rokarolla uses 137 distinct C2 commands, drops its payload via fake TikTok and Chrome installers, and actively suppresses Google Play Protect with commands such as disable_google_play and protectorgoogle_disable. The trojan also employs snapshot-based screen monitoring — capturing screenshots at intervals rather than live casting — and blocks incoming calls from financial institutions to prevent fraud alerts. Zimperium published IoCs including domains beralisvc.info and blestorians.cfd, giving defenders concrete indicators to hunt with.

Zimperium's full technical report, published alongside the initial disclosure, provides a detailed breakdown of Rokarolla's 137-command set, including the ability to block incoming calls and mute device audio to suppress fraud alerts. The researchers also released a complete list of indicators of compromise (IoCs) on GitHub, along with the full MITRE ATT&CK mapping for the attack chain, enabling defenders to detect and block the trojan more effectively.

Malwarebytes' analysis adds new detail on Rokarolla's distribution method: the malware is delivered via rogue websites offering fake versions of popular apps like TikTok or Chrome, which then pose as Google Play Protect to request dangerous permissions including Accessibility access. The report also highlights previously unreported capabilities such as the ability to replace copied cryptocurrency wallet addresses with attacker-controlled ones and to block security alerts by taking control of text messages and phone calls.

Zimperium's report, published on June 18, 2026, provides additional technical details on Rokarolla's distribution method: the trojan is delivered via malicious websites masquerading as popular apps like Chrome and TikTok, with the payload impersonating Google Play Protect. The malware also disables Google Play Protect, hides its icon from the app drawer, and mutes all device audio and vibrations to operate silently during fraudulent transactions, masking security alerts and verification calls from banks.

This new report details Rokarolla's sophisticated capabilities, including its use of HTML-based phishing overlays to mimic legitimate banking and cryptocurrency apps and its abuse of Android Accessibility Services for automated data theft. It also highlights the trojan's ability to swap cryptocurrency wallet addresses and block fraud alert calls, significantly increasing the risk to financial accounts.

Synthesized by Vypr AI