3Corns

New Android Malware Campaign “Rokarolla” Harvests PINs, SMS Codes, and Crypto Wallet Data
Security researchers at Zimperium’s Labs have identified a new Android banking trojan dubbed Rokarolla, designed to aggressively target users of 217 banking and cryptocurrency applications. The malware reportedly includes 137 remote commands, giving operators extensive control over infected devices. In practice, this translates into near-total device compromise. Rokarolla can extract lock-screen PINs, intercept and send SMS messages, manipulate the clipboard to redirect cryptocurrency transactions, and even disable Google Play Protect—essentially treating Android’s built-in defenses as optional suggestions. The malware is distributed through malicious websites impersonating popular apps such as TikTok and Chrome. Once installed, victims are first tricked into running a dropper disguised as Google Play Protect. This decoy helps the malware obtain Accessibility permissions, which it then exploits to deploy its payload and disable Play Protect entirely—because nothing says “trust me” like pretending to be your security software. Rokarolla’s primary attack method relies on overlay phishing. The malware retrieves a list of targeted apps from its command-and-control server, then downloads fake HTML login pages for each one. When a victim opens a legitimate banking or crypto app, Rokarolla overlays a counterfeit interface on top, silently capturing everything entered—including passwords and card details. Researchers observed one such overlay mimicking the banking app “imagin.” Another fake interface replicates the Android lock screen, allowing attackers to harvest PINs, patterns, and passwords—effectively turning device unlock into an unintended “group project.” The malware also reads and sends SMS messages, enabling it to intercept one-time passcodes used for banking authentication. By setting itself as the default messaging and calling app, it can additionally suppress incoming calls—meaning even a bank’s fraud alert might politely fail to make it through. Beyond credential theft, Rokarolla functions as a full surveillance toolkit. A keylogger and screen logger capture user activity, while contacts and notifications are exfiltrated. The clipboard is silently rewritten, replacing copied cryptocurrency wallet addresses with attacker-controlled ones—an especially subtle form of “creative accounting.” For stealth, Rokarolla avoids Android’s MediaProjection API, which typically triggers visible recording prompts. Instead, it leverages Accessibility services to capture screenshots, compresses them into PNG files, and exfiltrates them frame by frame. It is less “Hollywood hacker movie,” more “quietly taking notes in the background while you tap away.” The malware also includes multiple fallback command-and-control domains, allowing operators to swap infrastructure quickly if one server is taken down. Its 137-command capability exceeds earlier banking trojans such as HOOK, reflecting an increasingly modular and industrialized approach to Android malware development. As with most modern banking trojans, there is no traditional “patch” for users to install. Defenses remain straightforward: install apps only from Google Play, keep Play Protect enabled, and treat any unexpected Accessibility permission request as a serious warning sign—because in this case, it really is the master key. Zimperium reports that its security products detect Rokarolla, and indicators of compromise have been published in its GitHub repository. The company did not attribute the malware to any specific threat actor. However, the design clearly reflects intent: a highly engineered banking trojan built to bypass exactly the protections users are told to rely on—from Play Protect all the way down to the lock screen. In short, it behaves less like a “buggy app” and more like a very determined digital pickpocket with a full toolkit and surprisingly good patience. Source 🔗: https://thehackernews.com/2026/06/new-rokarolla-android-malware-steals.html