Security News > 2023 > April > New Chameleon Android malware mimics bank, govt, and crypto apps
A new Android trojan called 'Chameleon' has been targeting users in Australia and Poland since the start of the year, mimicking the CoinSpot cryptocurrency exchange, an Australian government agency, and the IKO bank.
The mobile malware was discovered by cybersecurity firm Cyble, which reports seeing distribution through compromised websites, Discord attachments, and Bitbucket hosting services.
Chameleon includes a wide range of malicious functionality, including stealing user credentials through overlay injections and keylogging, cookies, and SMS texts from the infected device.
If the environment appears clean, the infection continues, and Chameleon requests the victim to permit it to use the Accessibility Service, which it abuses to grant itself additional permissions, disable Google Play Protect, and stop the user from uninstalling it.
At first connection with the C2, Chameleon sends the device version, model, root status, country, and precise location, probably to profile the new infection.
Chameleon is an emerging threat that may add more features and capabilities in future versions.
News URL
Related news
- Android malware "FakeCall" now reroutes bank calls to attackers (source)
- Crypto-stealing malware campaign infects 28,000 people (source)
- TrickMo malware steals Android PINs using fake lock screen (source)
- Perfctl malware strikes again as crypto-crooks target Docker Remote API servers (source)
- Russia targets Ukrainian conscripts with Windows, Android malware (source)
- New FakeCall Malware Variant Hijacks Android Devices for Fraudulent Banking Calls (source)
- New Android Banking Malware 'ToxicPanda' Targets Users with Fraudulent Money Transfers (source)
- North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS (source)
- North Korean hackers use new macOS malware against crypto firms (source)
- Cyber crooks push Android malware via letter (source)