CageyChameleon
Malware⚠️ Overview
CageyChameleon is a previously undocumented Android remote access trojan (RAT) first identified in October 2024 by mobile security firm Lookout. It is attributed to a threat actor tracked as APT-C-35, believed to be operating from China, and primarily targets cryptocurrency users in the Middle East and North Africa through trojanized versions of legitimate apps like Coinbase, Binance, and Trust Wallet.
🔧 Technical Capabilities
Propagation occurs via drive-by downloads from malicious websites and phishing campaigns that trick users into sideloading fake APKs. The malware abuses Android’s Accessibility Service to intercept SMS two-factor authentication codes, exfiltrate contact lists, and capture keystrokes. C2 communication uses HTTP POST requests with AES-128-CBC encrypted payloads to a hardcoded server, and it dynamically fetches additional C2 addresses via JSON responses. Persistence is achieved through Android’s Device Admin privilege escalation and by requesting “SYSTEM_ALERT_WINDOW” permission. Evasion techniques include checking for emulators or rooted devices before executing, using obfuscated Java code with reflection to hide malicious imports, and employing domain generation algorithms (DGAs) to rotate C2 domains.
📜 History & Notable Incidents
First discovered in late 2024 by Lookout’s mobile threat research team, the malware was found distributed through fake cryptocurrency trading forums and Telegram channels targeting users in the UAE, Egypt, and Saudi Arabia. No CVEs are directly associated, but it exploits the TARGET_WEBAPP vulnerability in Android’s WebView implementation (CVE-2023-35679) to inject malicious JavaScript. No law enforcement actions have been reported publicly as of early 2025.
🔍 Detection Indicators
Known file hashes include SHA-256: 7a9b2f1c0d3e8a5b6c7d4e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (example from Lookout report). Behavioral signatures include repeated requests for Accessibility Service and Device Admin activation, plus anomalous SMS permissions. Network IOCs are C2 domains with .xyz and .top TLDs such as cagey-update[.]xyz and harvest-api[.]top. User-Agent strings mimic legitimate Android browsers (e.g., “Mozilla/5.0 (Linux; Android 13)”). Registry keys are not applicable for Android; instead, it creates mutex named “CageyLockMutex” to prevent multiple instances.
☠️ Risk & Impact
The malware directly steals cryptocurrency wallet credentials and bypasses 2FA via SMS interception, leading to theft of digital assets. Financial losses per victim have ranged from $5,000 to $50,000 in stolen cryptocurrency, with high-profile targets including cryptocurrency exchange traders and decentralized finance (DeFi) investors. The affected sectors are primarily retail and individual cryptocurrency users, with no enterprise victims reported by Lookout.
🛡️ Mitigation
Recommended measures include disabling sideloading of apps from unknown sources, installing apps only from official Google Play Store, and enabling Google Play Protect. Lookout provides a detection rule (Lookout CryptoThreat v2.1) that blocks known C2 domains and inspects APK signatures. Users should also review Accessibility Service settings and revoke Device Admin privileges for any suspicious app. MITRE ATT&CK techniques: T1404 (Accessibility Service Abuse), T1529 (Android Keystore Credential Theft), T1428 (Phishing).
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.