Chameleon

MITRE ATT&CK: S1083 View on attack.mitre.org

Aliases: Chameleon

First seen
2023-01-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:04:59

Targeted industries: financial-services

Targeted regions: country_code:au country_code:pl country_code:gb country_code:it

Context

Chameleon is an Android banking trojan that can leverage Android’s Accessibility Services to perform malicious activities. Believed to have been first active in January 2023, Chameleon has been observed targeting users in Australia and Poland by masquerading as official applications. A new variant of Chameleon has expanded its targets to include Android users in the United Kingdom and Italy.

Malware & tools used

  • Native API (attack-pattern)
  • Indicator Removal on Host (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Abuse Accessibility Features (attack-pattern)
  • Data from Local System (attack-pattern)
  • Scheduled Task/Job (attack-pattern)
  • Call Control (attack-pattern)
  • Phishing (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Checks (attack-pattern)
  • Application Layer Protocol (attack-pattern)
  • Web Protocols (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Location Tracking (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Access Notifications (attack-pattern)
  • Software Discovery (attack-pattern)
  • SMS Messages (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Keylogging (attack-pattern)
  • Screen Capture (attack-pattern)
  • Prevent Application Removal (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Lockscreen Bypass (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Chameleon (report)
  • threatfabric.com — Chameleon Is Now Targeting Employees Masquerading As Crm App (report)
  • blog.cyble.com — Chameleon A New Android Malware Spotted In The Wild (report)
  • threatfabric.com — Android Banking Trojan Chameleon Is Back In Action (report)
  • MITRE ATT&CK — S1083 (report)
  • cyble.com — Chameleon A New Android Malware Spotted In The Wild (report)

External references