Rokarolla changes the threat model from stolen logins to a compromised phone that can carry out fraud on its own. Once it controls the handset, SMS codes, bank alerts, and warning calls stop being reliable, because the malware can swallow them before the user sees them.
Zimperium’s zLabs says Rokarolla targets 217 banking and crypto apps and uses 137 commands. It abuses Android accessibility and default-handler settings to place fake login screens over real apps, capture PINs and one-time codes, block calls, mute alerts, rewrite crypto clipboard data, and take screenshots for surveillance.