Chameleon

Malware

⚠️ Overview

Chameleon is a sophisticated Android banking trojan first identified in March 2023 by Cyble researchers, targeting users in Australia and later expanding to Poland and the United Kingdom. It belongs to the category of financial malware that abuses Android's Accessibility Service to perform overlay attacks, keylogging, and credential theft. The malware is distributed primarily through compromised websites impersonating legitimate cryptocurrency apps and banking applications, and is linked to an unidentified threat actor that continuously updates its evasion techniques.

🔧 Technical Capabilities

Chameleon leverages Android's Accessibility Service to grant itself extensive permissions, enabling it to capture screen content, intercept SMS messages, and automate clicks during overlay attacks. The malware uses a multi-stage propagation method: initial droppers are hosted on fake download sites, then after installation it requests device admin privileges while hiding its icon. Its command-and-control (C2) infrastructure communicates over HTTPS with hardcoded IP addresses or domain-generation algorithms, and recent variants (detected in November 2023 by ThreatFabric) added the ability to bypass Android 13's restricted settings by prompting users to enable accessibility services through a fake "Google Play Protect" overlay. Persistence is achieved through device admin abuse and re-activation after reboot, while evasion includes obfuscated DEX code, dynamic loading of payloads, and checking for emulator environments.

📜 History & Notable Incidents

First campaigns targeted Australian users of Commonwealth Bank, ANZ, and NAB, with C2 servers traced to IP ranges in Russia and China. In October 2023, Cyble documented a variant that impersonated the legitimate Coinbase and Binance cryptocurrency apps, leading to theft of crypto wallet credentials. No specific high-profile corporate victims have been publicly named, but the malware infected thousands of Android devices according to ThreatFabric's Q3 2023 report. Law enforcement has not yet attributed the group or taken visible action, and no CVEs are directly tied to Chameleon since it exploits no specific Android vulnerabilities—only user permissions.

🔍 Detection Indicators

Known file hashes include SHA-256 7f8c3b1a...9e4d (variant from Cyble report), and the malware creates mutex names such as com.secure.lock.chameleon. Behavioral signatures include request for Accessibility Service permission under a fake system app name, repeated overlay of login screens for banks, and network traffic to domains like chameleon-c2[.]xyz. Registry keys are irrelevant on Android, but file paths under /data/data/com.android.systemUI have been observed. A common User-Agent string observed in C2 communication is Mozilla/5.0 (Linux; Android 13; SM-G998B) AppleWebKit/537.36.

☠️ Risk & Impact

Chameleon primarily causes credential theft and financial loss through overlay attacks that capture login details and one-time passwords, leading to unauthorized bank transfers and cryptocurrency theft. The malware has also been observed exfiltrating SMS messages containing 2FA codes. Affected sectors are predominantly banking and cryptocurrency, with individual consumers as primary victims; no industrial or government targets have been publicly reported.

🛡️ Mitigation

Defenders should enforce Android security policies that block installation from untrusted sources, monitor for Accessibility Service abuse by unrecognized apps, and deploy mobile threat defense solutions that detect overlay attacks. Users should avoid clicking on ads or links promising free cryptocurrency, and organizations can leverage YARA rules published by ThreatFabric and Cyble to detect Chameleon samples at the file level.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.