
Despite the protections implemented by antivirus publishers and the vigilance of users, some malicious applications manage to slip through the cracks. This situation is especially new Chameleon versionA formidable trojan was already detected in April 2023. At that time, the malware was already acting as a keylogger, capable of stealing your SMS or attacking your cookies.
Today’s new version of Chameleon goes even further: can bypass fingerprint unlock on Android smartphones and get user PIN. And the worst part is that no protection solution can prevent this, at least for now. An explanation of how it works is required.
How does Chameleon malware manage to protect itself so easily?
chameleon is coming Zombinder, a darknet platform that distributes malware disguised as legitimate Android applications. This platform generally uses a fairly simple but extremely effective technique: it simulates a freely accessible Wi-Fi point. In the case of Chameleon, Zombinder distributes a fake version of the Chrome browser; this version is fully functional, but still appears legitimate in the eyes of the system and its guards.
However, Chameleon needs Android accessibility rights to work fully. However, starting from Android 13, these rights are blocked by default. Therefore, a short HTML tutorial was created for the user by the authors of Chameleon, showing them the procedure to follow to grant the necessary rights. So yes, the smartphone owner needs to intervene. However, the victim easily falls into the trap thinking that he is using a legitimate version of Chrome.
An undetectable trojan that can disable all biometric protections
From then on, the trojan can operate with peace of mind. The malware, thanks to the rights granted to accessibility services in its new version smartphone unlocking protectionsWhether with fingerprint or face recognition. The user then has no choice but to opt for PIN code or password authentication. Chameleon then instantly records the actions performed on the smartphone (remember, this is an excellent keylogger). Since it is initially a banking malware, it will happily collect the user’s details to gain access to the bank account.
Malware installation cannot be detected in real time. Whether through an antivirus or the Google Protection solution, Chameleon goes completely undetected. Some advice: To protect yourself from such malicious apps, avoid at all costs installing any APK from a dubious platform like Zombinder. Finally, feel free to regularly initiate analysis of your smartphone using Google’s analysis tools or those of a third-party security solution, if available.
Source : Threat Fabric
Support our work ❤️
If you enjoyed this article, consider leaving a tip to help us keep publishing great content.

























