Chameleon is an Android banking trojan and device-takeover malware first identified in late 2022 and active from at least January 2023. It has targeted mobile users in Australia, Poland, Canada, and Europe, including customers of financial institutions and employees who may access business banking accounts. It masquerades as cryptocurrency, banking-security, government, browser, AI, and customer-relationship-management applications. Observed distribution has included compromised websites, Discord attachments, code-hosting services, and multi-stage droppers that bypass Android 13+ installation and Accessibility-service restrictions.
Chameleon abuses Android Accessibility Service to automate permission grants, interfere with uninstallation, disable Google Play Protect, capture keystrokes, and conduct overlay attacks against selected applications. It can load attacker-supplied HTML phishing pages in WebView overlays to steal banking credentials, identify device screen-lock types and capture entered PINs, passwords, or patterns, steal browser session cookies, and intercept SMS messages, including one-time authentication codes. The malware also profiles infected devices, collecting attributes such as operating-system version, model, root status, country, and location, and collects device logs. Stolen data is transmitted to command-and-control infrastructure over HTTP. Chameleon also contains a runtime payload-loading capability, although this functionality was not observed being used in the analyzed implementation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le panel CSuite v1.1 comporte le module « Chameleon », avec 216 victimes uniques, et des fonctions de portail de redirection, d’anti-bot et de routage des victimes.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Brain обладал механизмами сокрытия своего присутствия; полиморфные вирусы изменяли своё представление при распространении, снижая эффективность статических сигнатур.
These campaigns introduced an unusual masquerading technique used in the campaign targeting Canada: masquerading as a Customer Relationship Management (CRM) app.
Once loaded, the dropper displays a fake page masquerading as a CRM login page, requesting the Employee ID... After installation, a fake website is loaded, again asking for the credentials of the employee.
Because Chameleon is already running in the background, it is also able to collect credentials and other sensitive information using keylogging.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
Once loaded, the dropper displays a fake page masquerading as a CRM login page, requesting the Employee ID... After installation, a fake website is loaded, again asking for the credentials of the employee.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Module/outillage de phishing de l’écosystème CSuite, employé pour les redirections, le filtrage des victimes et les pages de collecte d’identifiants et de sessions.
... Chameleon ... (v1.0→v2.0) ...
Chameleon (v1.0→v2.0)
Banking trojan referenced only for comparison of overlay attack behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.