Researchers at cybersecurity firm Cyble have identified a novel Android trojan that can camouflage as other apps. In a blog post published on April 13, the researchers said the new Android banking trojan, named “Chameleon,” has been used to target users in Australia and Poland since January 2023.
Chameleon is an advanced trojan with various functionalities, including keylogging, SMS message harvesting, browser cookie theft, and more. Apart from camouflaging as other apps to evade detection, the trojan also changes the system settings on a victim’s device to disable Google Play Protect and prevent the target from uninstalling it.
Cyble said the highly adaptable malware is spread via “compromised websites, Discord attachments, and Bitbucket hosting services.”
Chameleon has been used to target financial institutions, their customers, and employees. Cyble researchers said the malware is “in its early stages of development and has limited capabilities.”
“Its primary method of stealing users’ credentials is through injection and keylogging techniques,” Cyble said.
Chameleon’s Disguises and Capabilities
Chameleon “pretends to be the popular cryptocurrency app Coinspot, a government agency in Australia [the Australian Taxation Office], and IKO bank from Poland,” Cyble said in a blog post. It also uses the icons of popular software like Google Chrome, ChatGPT, and Bitcoin to stay under the radar.
Cyble listed a set of URLs used to distribute Chameleon. Chameleon appears to come in an Android APK installation file. APK files are the original format Android uses to install compatible software. APK files can be found on and installed from websites.
Chameleon’s other capabilities include overlay attacks and recording a victim’s lock screen pattern or password. The malware scans if a device is rooted or debugging is activated, and if so, it will cancel the infection process.
Cyble researchers believe the developers of Chameleon may add more features to improve its capabilities. This means Chameleon could be elevated to “the same category as prominent and prevalent Banking Trojans,” Cyble said.
How to Limit This Threat
Cyble listed a set of best practices for Android users to avoid falling victim to Chameleon. Among other things, Cyble recommends only downloading apps from the Google Play Store. Even then, you must be wary of compromised apps. Kaspersky released a report recently detailing how much cybercriminals charge on the dark web marketplaces to get “trojanize” apps on Google’s Play Store.
Teabot, one of the most popular banking trojan strains observed recently, was disguised as a QR Code & Barcode Scanner on the Google Play Store and downloaded over 10,000 times.
Alisa Kulishenko, a security expert at Kaspersky, told VPNOverview that users should be wary of apps that ask for permissions that don’t match their functionality.
“For instance, they should pay special attention to how many downloads this app has and what permissions this app asks, especially when it comes to high-risk permissions such as Accessibility Service,” she said.
Take a look at our ultimate Android malware removal guide to understand how malware spreads and the exact tools required to limit infections that could put your identity and finances at risk.
