No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Chameleon Banking Trojan Makes a Comeback Cloaked as CRM App

August 7, 2024
in Protection
0
Chameleon Banking Trojan Makes a Comeback Cloaked as CRM App


The Chameleon Android banking Trojan is back on the threat scene, armed with new Android security-bypass features. The malware poses as a customer relationship management (CRM) application and targets employees in the hospitality sector and other business employees on two continents.

Researchers from Threat Fabric revealed that the device-takeover Trojan is targeting “hospitality workers and potentially B2C business employees in general” across Canada and Europe. Researchers say the new variant uses a dropper that can bypass Android 13+ AccessibilityService restrictions.

The Trojan is targeting a popular restaurant chain in Canada, which operates globally, to get access to corporate banking accounts, which would pose a “significant risk” to the organizations breached, according to Threat Fabric.

“The increased likelihood of such access for employees whose roles involve CRM is the likely reason behind the choice of the masquerading during this latest campaign,” according to a blog post from Threat Fabric.

Researchers also see evidence of attacks that target “customers of specific financial organizations” in which Chameleon masquerades as a security application to install a security certificate released by the victims’ banks as part of the malware’s resurgence.

Shape-Shifting Malware

Security researchers first detected Chameleon — which got its name for its ability to adapt to its environment through multiple new commands — around December 2022/January 2023, when it appeared in its earliest form as a work in progress. Except for an appearance late last year with a significantly more fully featured variant that could bypass biometric security, the malware has been flying under the radar.

Now it has evolved yet again, with new features that show how its operators are changing the malware to keep up with the Android OS as it also becomes fortified with advanced security features.

According to the Threat Fabric post, “Most significant is the Trojan’s ability to bypass Android 13+ restrictions, which once again proves the prediction we made in the past — this capability has become essential for modern banking Trojans.”

Chameleon’s use of the BrokewellDropper for delivery is significant to this bypass; indeed, since the leak of the source code for the dropper — which has an extensive set of device-takeover capabilities — more threat actors now have access to security bypass on the Android OS, according to Threat Fabric.

Trojan’s Latest Disguise

Chameleon’s most recent disguise should be no surprise to security researchers tracking the Trojan, as the malware, like other Trojans, has historically impersonated trusted apps. Previously, Chameleon came cloaked as an app from institutions such as the Australian Taxation Office (ATO) or one of several popular banking apps in Poland to steal data from user devices.

Once loaded, the dropper displays a fake page masquerading as a CRM login page, requesting the employee ID. It then displays a message asking to reinstall the application, which is actually Chameleon, which installs and bypasses Android AccessibilityService restrictions. After installation, the Trojan loads a fake website again asking for the employee’s credentials. If submitted, the app displays an error page, according to Threat Fabric.

Chameleon remains running in the background on a device, which means it can also collect other credentials and sensitive info from a user by using keylogging. “Such information can be used in further attacks or the actors can monetise it by selling  it on underground forums,” according to the post.

More Sophisticated Attacks

The latest Chameleon campaign demonstrates how Trojan-wielding cybercriminals are finding new and innovative ways to target bigger assets beyond the banking credentials of individual mobile users, according to Threat Fabric. This should put all organizations on high alert to the evolving mobile threat landscape.

“With the rising number of banking products for businesses (especially small and medium) and the convenience of having them available through mobile, we can expect cybercriminals to further explore the approach of targeting such mobile devices and its users,” according to the post.

To combat these threats, financial organizations can take preventive measures to educate business customers about the potential impact of mobile banking malware like Chameleon and the consequences these malicious apps can bring, according to Threat Fabric. Moreover, given their visibility into customers’ financial accounts, banks should also become more proactive in spotting anomalies in activity and behavior to stop threats before they compromise accounts.



Editorial Team

Editorial Team

Related Posts

All the New Features Coming to Messages in iOS 27
Protection

All the New Features Coming to Messages in iOS 27

June 12, 2026
30 of the Gayest Straight Movies Ever Made
Protection

30 of the Gayest Straight Movies Ever Made

June 12, 2026
These Insignia QLED TVs Are 40% Off Right Now
Protection

These Insignia QLED TVs Are 40% Off Right Now

June 12, 2026
My Apple Watch Doesn’t Support watchOS 27, but Here’s Why I’m Not Buying a New One
Protection

My Apple Watch Doesn’t Support watchOS 27, but Here’s Why I’m Not Buying a New One

June 12, 2026
Five Hacks Every Meta Smart Glasses User Should Know
Protection

Five Hacks Every Meta Smart Glasses User Should Know

June 12, 2026
Apple’s Image Playground Just Caught Up to ChatGPT and Gemini
Protection

Apple’s Image Playground Just Caught Up to ChatGPT and Gemini

June 12, 2026
Load More
Next Post
Condé Nast Traveler

Airbnb's Newest Icon Property Is a Life-Sized Polly Pocket Compact

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • 8 Best Financial Advisors in Milwaukee, Wisconsin for 2023 • Benzinga

    0 shares
    Share 0 Tweet 0
  • 5 Things to Know About the Seen Mastercard

    0 shares
    Share 0 Tweet 0
  • CoinShares Litecoin ETF moves forward as SEC begins formal review

    0 shares
    Share 0 Tweet 0

Latest News

Anthropic staff to meet White House officials next week, Axios reports

Anthropic staff to meet White House officials next week, Axios reports

June 14, 2026
0

Anthropic staff to meet White House officials next week, Axios reports

Trump says he is against FISA extension if voting bill not attached

Trump says he is against FISA extension if voting bill not attached

June 14, 2026
0

Trump says he is against FISA extension if voting bill not attached

Why Brad Garlinghouse believes the CLARITY Act will pass in May despite missing two deadlines - 1

Ripple targets $1B revenue run rate without counting XRP holdings

June 14, 2026
0

Ripple CEO Brad Garlinghouse has put a clear number on the company’s 2026 business goal.  Summary Ripple’s revenue target separates...

spacex satellite launch crypto

Tokenized SpaceX Share Allocations Canceled After Broker Shortage Hits Crypto Platforms

June 14, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Primary source update embedded from X. ...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.