logo

Chameleon Android Banking Trojan Variant Bypasses Biometric Authentication

ID: a859bb2e-1ae6-5ff4-8f0d-ba2223ba0bfa

STIX ID: report--a859bb2e-1ae6-5ff4-8f0d-ba2223ba0bfa

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2023-12-21

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** An evolved Android banking trojan named Chameleon has resurfaced with expanded targeting (U.K., Italy) and enhanced Device Takeover capabilities using Android's accessibility service; it is being distributed via the Zombinder dropper-as-a-service and includes new functionality to prompt Android 13 users to enable accessibility and covertly switch biometric locks to PINs to enable unauthorized unlocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.