Monday, January 27, 2025
HomeAndroidChameleon Device-Takeover Malware Attacking IT Employees

Chameleon Device-Takeover Malware Attacking IT Employees

Published on

SIEM as a Service

Follow Us on Google News

Researchers have identified a new Chameleon campaign targeting hospitality employees, where the attackers employed a deceptive tactic, disguising malicious software as a CRM app. 

File names uploaded to VirusTotal revealed evidence of targeted attacks, including a reference to a prominent international restaurant chain. This suggests a tailored approach to compromising specific organizations within the hospitality industry. 

Masquerading as CRM

Conventions regarding the naming of droppers and payloads indicate that the campaign is aimed at the hospitality industry and possibly more general business-to-consumer sectors. 

Successful infection of devices with corporate banking access grants the Chameleon malware control over business accounts, posing a significant organizational risk.

Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Free Access

The campaign’s focus on CRM-related employee roles likely increases the probability of such access, making them high-value targets for attackers. 

A newly identified dropper capable of circumventing Android 13’s security restrictions marks a critical evolution in banking Trojan capabilities. 

This development underscores the increasing accessibility of Android bypass techniques following the public release of BrokewellDropper’s source code.

Upon activation, a malicious dropper presents a fraudulent CRM login screen demanding an employee ID. Subsequently, a deceptive prompt encourages application reinstallation, which is subterfuge, while the application secretly installs a Chameleon payload. 

The payload circumvents the fortified security measures implemented in Android 13 and later versions, specifically targeting accessibility service restrictions to establish a covert foothold within the device. 

fake page

A malicious actor deployed a fake website post-installation, prompting users for credentials.

Upon submission, the website displayed an error message indicating potential credential harvesting or further malicious activity beyond credential acquisition. 

Chameleon malware, actively operating in the background, employs keylogging to steal credentials and sensitive information. It poses a significant threat that can be exploited for further attacks or sold illicitly. 

Mobile Threat Intelligence has identified Chameleon targeting specific financial institutions, disguising itself as a security app to install a fraudulent security certificate, emphasizing the malware’s evolving tactics and the critical need for robust countermeasures. 

Cybercriminals are increasingly targeting employees of B2C businesses to gain access to business banking accounts via mobile devices.

As exemplified by malware like Chameleon, the proliferation of mobile banking products for SMEs creates new opportunities for attackers. 

According to ThreatFabric, financial institutions must proactively educate business customers about these threats, emphasizing the potential consequences of malware infection. 

By implementing robust anomaly detection systems and malware detection capabilities, banks can enhance visibility into customer accounts, safeguarding assets from unauthorized access and fraudulent activities. 

How to Build a Security Framework With Limited Resources IT Security Team (PDF) - Free Guide

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

White House Considers Oracle-Led Takeover of TikTok with U.S. Investors

In a significant development, the Trump administration is reportedly formulating a plan to prevent...

Critical Vulnerability in IBM Security Directory Enables Session Cookie Theft

IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory...

Critical Apache Solr Vulnerability Grants Write Access to Attackers on Windows

A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through...

GitHub Vulnerability Exposes User Credentials via Malicious Repositories

A cybersecurity researcher recently disclosed several critical vulnerabilities affecting Git-related projects, revealing how improper...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

White House Considers Oracle-Led Takeover of TikTok with U.S. Investors

In a significant development, the Trump administration is reportedly formulating a plan to prevent...

Critical Vulnerability in IBM Security Directory Enables Session Cookie Theft

IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory...

Critical Apache Solr Vulnerability Grants Write Access to Attackers on Windows

A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through...