The mobile threat landscape just got significantly more dangerous. Security researchers have uncovered a sophisticated Android banking trojan named Rokarolla — and it doesn't just steal your passwords. It seizes your entire device, silences your bank's warnings, hijacks your crypto transfers, and locks you out of your own phone while attackers operate freely in the background. If your organisation manages a fleet of Android devices, this threat demands your immediate attention.


What Is the Rokarolla Android Trojan?

The zLabs research team at mobile security firm Zimperium discovered Rokarolla — a newly identified Android banking trojan named after its Command and Control (C2) infrastructure.

Unlike older banking malware that simply phishes for credentials,

this newly discovered Android banking trojan goes beyond draining accounts, seizing near-total control of a phone and cutting victims off from their banks so fraud can run undetected.

Named Rokarolla after its C2 servers, the malware was detailed by zLabs and found to be targeting 217 banking and cryptocurrency apps through a toolkit of 137 commands.

To put that in perspective,

its 137 commands outnumber the 107 Zimperium counted in the HOOK trojan

— itself one of the most sophisticated Android banking trojans previously documented.


How Rokarolla Infects Devices

Understanding the infection chain is the first step to stopping it.

The malware is distributed via malicious websites purporting to provide the Google Chrome or TikTok app, and can take complete administrative control of a compromised device.

During the installation process, the malicious app acts as a dropper and impersonates Google Play Protect — Android's built-in anti-malware system — offering users the option to install Chrome or TikTok, which contain the Rokarolla malware.

It's a clever social engineering trick: the very tool users trust to keep them safe becomes the vehicle for infection.

The malware also maintains multiple fallback command-and-control domains and can receive new ones on the fly, so taking down a single server does little to disrupt operations.

This resilience makes it extremely difficult for defenders to neutralise via traditional blocklist approaches.


The Full Scope of Rokarolla's Capabilities

What makes Rokarolla truly alarming is the breadth of its attack surface.

To facilitate undetected financial fraud, Rokarolla employs a sophisticated suite of 137 commands that grant it extensive administrative control over an infected device. Its malicious capabilities include harvesting lock screen credentials, exfiltrating sensitive contact lists and SMS data, and utilising keyloggers to continuously record user input.

Device Lockout and Surveillance

The malware also makes the device virtually unusable by its owner, actively concealing its operations and disrupting user intervention by blocking incoming calls, deploying fraudulent screen overlays, suppressing device audio, and deactivating Google Play Protect.

For surveillance, rather than streaming the screen live, Rokarolla quietly takes timestamped screenshots and exfiltrates them one by one

— a method that avoids triggering Android's screen-recording permission prompts.

Cryptocurrency Theft

Rokarolla also performs clipboard hijacking to modify text copied by the user, switching cryptocurrency wallet addresses during transfers without the victim noticing.

This means even security-conscious users who carefully type wallet addresses can still be defrauded if they copy-paste at any point during a transaction.

Fake Lock Screen Credential Theft

The malware can display a fake Android lock screen designed to collect the victim's PIN, pattern, or password. Once obtained, attackers can unlock the phone remotely and continue controlling the infected device — changing the threat from a simple banking trojan into a complete surveillance platform.

SMS Interception Defeats MFA

The research shows the changing trends in mobile threats, as cybercriminals don't focus entirely on data theft and instead aim for full device takeover. This is a worrying trend because controlling a phone's audio and text messages makes security features like multi-factor authentication completely useless.


Why This Threat Is Especially Dangerous for Mobile Fleets

Rokarolla doesn't just threaten individual consumers — it poses a serious risk to enterprises managing fleets of Android devices, including BYOD (bring-your-own-device) programmes.

"Because it targets financial workflows (fake windows for banks) and abuses the SMS handler role for intercepting two-factor SMS, it poses a direct threat to enterprise customers using BYOD and to any organisation whose employees rely on mobile banking or sensitive mobile apps."

The broader threat landscape reinforces the urgency.

According to a Kaspersky report, the number of Trojan banker attacks on Android smartphones increased by 56% in 2025 compared to the previous year.

Furthermore,

the number of new Trojan banker installation packages for Android also increased sharply, reaching 255,090 packages — a 271% increase over 2024.

Android banking trojans using identical techniques have already been found embedded in fake streaming apps targeting World Cup 2026 fans

— demonstrating how rapidly threat actors adapt their lures to current events.


Practical Tips to Protect Your Mobile Fleet Right Now

Whether you're a security manager, IT administrator, or individual Android user, these actionable steps can dramatically reduce your exposure to Rokarolla and similar threats.

1. Block Sideloading and Enforce App Allowlisting

Block sideloading and enforce app allowlisting on managed devices to prevent installation of unvetted APKs from GitHub, forums, or direct links.

Rokarolla spreads exclusively via malicious third-party sites, not the official Google Play Store — so preventing sideloading removes its primary infection vector.

2. Restrict Dangerous Permissions

Restrict high-risk permissions — especially Accessibility Services, device admin access, and overlay capabilities — and monitor devices for apps requesting them.

Rokarolla relies heavily on Accessibility Services abuse to execute its commands; cutting off this permission kills much of its functionality.

3. Deploy Mobile Threat Defence (MTD) Solutions

Use MDM/EMM controls to detect and block suspicious apps, enforce minimum OS versions, and require secure configurations such as screen locks and encryption. Deploy mobile threat defence solutions that identify behavioural indicators like keylogging.

Signature-based antivirus alone is not sufficient against evolving, polymorphic threats like Rokarolla.

4. Keep Android OS Fully Updated

Anyone running Android 12 or earlier on their device is particularly vulnerable. Google ended security updates for that version in March 2025.

Ensure all devices in your fleet are running a currently supported Android version with the latest security patches applied.

5. Train Employees to Spot Fake App Pages

Be extremely cautious with permissions like SMS access, notification access, Accessibility, and "Display over other apps," which show up again and again in infostealers, banking trojans, and OTP-stealing campaigns.

Regular security awareness training should specifically address fake app download sites and impersonation of trusted brands like Chrome and TikTok.

6. Treat Mobile Like a Primary Attack Surface

Android users — and the organisations that manage their devices — need to treat mobile security with the same seriousness as desktop and server environments. Malwarebytes research shows that people are 39% more likely to click a link on their phone than on their laptop.

That behavioural reality makes mobile devices an even higher-value target for attackers.


The Bigger Picture: A New Era of Mobile Banking Threats

"The Rokarolla trojan marks a shift from data theft to victim isolation," explained Jason Soroko, senior fellow at certificate-management firm Sectigo, who described Rokarolla turning the phone into a weapon against its owner.

This strategy "represents an evolution in threats," trapping the user in an environment in which they still have their phone, but it's out of their control, with the attacker dictating what information enters or leaves the device.

Traditional reactive security models — waiting for a known signature to appear — are no longer adequate against this class of adversary.

Researchers warned that as smartphones become the primary access point for financial services and apps, devices will continue to face banking malware campaigns, each with its own brand of exploitation and expanded capabilities to enable device takeover.


Conclusion: Don't Wait for the Next Rokarolla

Rokarolla is a watershed moment in Android malware development. It doesn't just steal — it isolates, surveils, impersonates, and controls. For IT and security teams managing Android device fleets, the message is clear: passive, perimeter-focused defences are obsolete. A proactive, layered mobile security strategy — combining MDM enforcement, app allowlisting, MTD solutions, and employee education — is no longer optional. It's essential.

Is your mobile fleet protected against the latest generation of Android banking trojans? Now is the time to audit your mobile security posture, close the gaps Rokarolla exploits, and implement a zero-trust approach to every device in your organisation. Contact a qualified mobile security specialist today — before a trojan makes that decision for you.