Back to news

Rokarolla Android Trojan and The Gentlemen Ransomware Raise Enterprise Alarm

Two newly documented threat actors — one targeting mobile banking apps, the other rapidly scaling ransomware operations — signal a more aggressive cybercrime landscape for businesses.

Rokarolla Android Trojan and The Gentlemen Ransomware Raise Enterprise Alarm

What happened

Zimperium's zLabs team has detailed a previously undocumented Android banking trojan called Rokarolla that sets its sights on 217 banking and cryptocurrency applications. The malware arms operators with 137 remote commands, enabling them to harvest device PINs, intercept and dispatch SMS messages, hijack the clipboard to silently redirect cryptocurrency transactions, and disable Google Play Protect. Separately, cybersecurity journalist Brian Krebs has published an investigation into The Gentlemen, a ransomware collective that has surged to become the second most prolific ransomware group by victim count. The group has grown quickly by offering affiliates a 90 percent cut of ransom proceeds, lowering the barrier for skilled hackers to join its ranks.

Why it matters for your business

Rokarolla represents a meaningful escalation in mobile-first financial threats: any employee who authenticates to corporate banking portals or crypto treasury tools from an Android device is a potential entry point. The clipboard-hijacking capability is particularly dangerous for organizations managing digital assets, since a single copied wallet address can be silently replaced mid-transaction with no visible warning. The Gentlemen's affiliate model, meanwhile, mirrors the industrialization seen in mature ransomware ecosystems — high revenue splits attract competent operators and compress the time between initial access and full network encryption. Operations leaders should treat both developments as a prompt to audit mobile device management policies, enforce hardware-backed authentication, and verify that endpoint detection tools cover Android fleets alongside traditional desktops.

What to watch next

Zimperium's disclosure is likely to prompt imitation: other threat actors may adapt Rokarolla's command architecture to target additional financial platforms or expand beyond Android to iOS environments. On the ransomware front, Krebs's reporting on the alleged administrator of The Gentlemen could accelerate law enforcement action, but historically such exposure also triggers rebrandings that temporarily obscure attribution. Tracking whether The Gentlemen's affiliate pool disperses or consolidates under a new banner will be a key indicator of the group's resilience.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp