New Android trojan called Rokarolla targets 217 banking apps and can steal your PIN, SMS codes, and crypto wallet funds
Zimperium's zLabs has documented Rokarolla, a new Android banking trojan targeting 217 apps and commanding 137 remote functions. It steals PINs, intercepts SMS, and hijacks cryptocurrency payments by overlaying fake login pages and rewriting the clipboard to swap wallet addresses. The malware spreads via fake websites impersonating popular apps like TikTok and Chrome, using a dropper disguised as Google Play Protect to install the main payload and gain Accessibility access. Rokarolla can disable Play Protect, read all SMS, block calls, and exfiltrate data through screenshots taken via Accessibility rather than a visible recording prompt. It maintains multiple fallback C2 domains to resist takedowns and is part of a broader 2026 trojan wave.






