Rokarolla: the dangerous Trojan that impersonates Google to steal your banking details

Last update: 20 June, 2026
  • Rokarolla is distributed through fake versions of popular apps like Chrome or TikTok.
  • The malware uses accessibility services to display fraudulent screens and steal passwords.
  • It is designed to attack more than 200 financial applications and cryptocurrency wallets.
  • Zimperium experts warn that it can intercept SMS messages and manipulate the device's clipboard.

Trojan threat on Android

The cybersecurity world has woken up to a new headache for Android users. It's Rokarolla, a banking Trojan detected by Zimperium that has put experts on alert due to its ability to silently empty accounts. This malware is no joke, as it has been specifically designed to trick users and gain complete control of their phones, particularly affecting those who use financial apps on a daily basis.

What makes this threat so dangerous is the way it sneaks onto our devices without us even noticing. Instead of being in the official app store, scammers use phishing websites that mimic legitimate download portals. There, they offer supposed updates for tools we all use, like Google Chrome or TikTok, but what you're actually downloading is a poisoned gift that will serve as a bridge to install the ultimate malware on your device.

How does Rokarolla manage to deceive the system?

Once the user takes the bait, the Trojan deploys its full arsenal to establish itself on the system. To avoid raising suspicion, it disguises itself as Google Play Protect , even using its official iconography to gain the user's trust. Under this false identity, the malware prompts the user to activate Android's accessibility services, a feature that, if compromised, allows the attacker to read everything on the screen and press buttons without the user lifting a finger.

If the user grants these permissions, the Trojan takes control. Thanks to this ability to control, Rokarolla monitors which applications are opened at any given time. Its primary target is a catalog of 217 applications, ranging from the most well-known banks in Spain and Europe to the most popular cryptocurrency platforms, waiting for the precise moment the user decides to check their savings.

Banking malware on smartphone

Advanced techniques for credential theft

The key trick of this malware is the use of dynamic screen overlays. When it detects that you're about to log into your bank, it places a fake HTML-based interface on top of the real application. The resemblance is so astonishing that it's almost impossible to tell the difference. When you enter your PIN or password, you're not giving the data to your bank, but rather sending it directly to the cybercriminals' servers, who can also capture your phone's lock pattern.

But it doesn't stop there, because this Trojan is a real digital snooper. Besides stealing passwords, it can intercept SMS messages and notifications , which is critical because it allows them to obtain the verification codes that banks send to authorize transfers. It's also capable of recording everything you type and snooping through your WhatsApp messages, completely destroying your privacy while operating silently in the background.

Cryptocurrency manipulation and passive monitoring

For those who trade digital assets, this malware holds a rather unpleasant surprise related to the clipboard. Rokarolla detects when you copy a crypto wallet address and invisibly replaces it with one belonging to the attackers. This way, if you're not careful before hitting send, you could be sending all your money to a stranger's account with no way to recover it—a scam that has already affected many unsuspecting users.

Instead of continuously recording video, which would drain your battery and raise suspicion, it uses a system that takes screenshots intermittently. This allows them to process the information with timestamps to know exactly what you were doing. Furthermore, to prevent the user from noticing the problem, the Trojan can hide its own icon, silence sound alerts, and even block incoming calls from the bank if they try to warn you that something unusual is happening with your account.

Keeping your mobile phone safe involves using common sense and remaining vigilant against supposed updates that arrive through unreliable channels. Being aware of these threats is crucial to protecting your savings and preventing a simple click from turning into a real financial headache. Therefore, it's always best to stick to official app stores and double-check the permissions you grant to each application.