Chameleon Banking Trojan Makes a Comeback Cloaked as CRM App
ID: 76c0b39e-82d0-565e-b1d8-956ba2483657
STIX ID: report--76c0b39e-82d0-565e-b1d8-956ba2483657
Feed Name: Dark Reading
Date Published: 2024-08-07
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers observed a resurgence of the Chameleon Android banking Trojan targeting hospitality and business customers in Canada and Europe; the campaign uses the BrokewellDropper to bypass Android 13+ AccessibilityService restrictions, masquerades as CRM or security apps to phish employee credentials, installs malicious certificates, runs in the background to keylog and exfiltrate sensitive information, and aims to access corporate banking accounts with potentially significant financial impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
