CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds

June 25, 2026

Security researchers at Zimperium’s zLabs have identified a new Android banking trojan named Rokarolla, which targets 217 banking and cryptocurrency apps and utilizes 137 remote commands. The malware grants operators near-total control over infected devices, enabling theft of lock-screen PINs, SMS messages, and cryptocurrency wallet funds.

Rokarolla spreads through malicious websites posing as legitimate apps like TikTok and Chrome. The initial dropper disguises itself as Google Play Protect to gain installation and Accessibility access. Once active, it disables Google Play Protect and uses HTML overlays to capture login credentials, card details, and lock-screen patterns. It also intercepts SMS one-time codes, blocks incoming calls, and silently rewrites clipboard content to redirect crypto payments to attacker-controlled wallets.

The malware employs a keylogger and screen logger, and takes screenshots via Accessibility without triggering visible prompts. It features multiple fallback command-and-control domains and can receive new ones dynamically. Zimperium notes that Rokarolla’s 137 commands exceed those of the HOOK trojan, and its tactics align with a broader wave of 2026 Android banking malware.

Defenses include installing apps only from Google Play, keeping Play Protect enabled, and treating unexpected Accessibility requests as suspicious. Zimperium’s products detect the family, and indicators of compromise are available in its GitHub repository.

CVEs: CVE-2026-11645

Malware: Rokarolla, HOOK

Companies: Zimperium

Products: Zimperium zLabs, Google Play Protect