Rokarolla is a newly documented Android banking trojan that targets about 217 banking and cryptocurrency applications, according to researchers at Zimperium. The malware is delivered primarily through malicious websites that impersonate legitimate apps—such as TikTok and Google Chrome—tricking users into installing what appears to be a real application. Once installed, Rokarolla connects to command-and-control infrastructure and supports at least 137 remote commands, enabling operators to gain extensive control over infected devices.

Across reporting, researchers say Rokarolla can harvest sensitive authentication and transaction data, including lock-screen PINs, SMS messages and related verification codes, and can also manipulate the device clipboard to redirect cryptocurrency payments. Some accounts also describe capabilities such as device surveillance, disabling or suppressing fraud alerts, and taking steps to maintain control over the compromised phone. SecurityWeek and other outlets characterize the malware as enabling near-total control when combined with its command set and persistence-related behavior.

Researchers name the trojan after its command-and-control infrastructure and report that it combines banking fraud with surveillance and remote control functions.