Chameleon Malware Poses as CRM App



phishing websiteResearchers at ThreatFabric warn that a phishing campaign is distributing the Chameleon Android malware by impersonating a Customer Relationship Management (CRM) app. The campaign is currently targeting users in Canada and Europe, but may expand to other regions.

“The naming used for the dropper and the payloads clearly shows that the intended victims of the campaign are hospitality workers and potentially B2C business employees in general,” ThreatFabric says.

“If the attackers succeed in infecting a device with access to corporate banking, Chameleon gets access to business banking accounts and poses a significant risk to the organisation. The increased likelihood of such access for employees whose roles involve CRM is the likely reason behind the choice of the masquerading during this latest campaign.”

Once the malware is installed, it continues to use social engineering to gain additional privileges on the device.

“Once loaded, the dropper displays a fake page masquerading as a CRM login page, requesting the Employee ID,” the researchers write. “Then a message asking to reinstall the application pops up, when in actual fact it installs a Chameleon payload, bypassing Android 13+ AccessibilityService restrictions.

After installation, a fake website is loaded, again asking for the credentials of the employee. At the time of writing this report, after submitting the credentials, an error message was displayed. Because Chameleon is already running in the background, it is also able to collect credentials and other sensitive information using keylogging.”

ThreatFabric concludes that “financial organisations can take preventive steps and educate business customers about potential impacts of mobile banking malware like Chameleon and the consequences it brings landing on a mobile device with access to business banking accounts.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

ThreatFabric has the story.


Free BreachSim Tool

How easy is it for bad actors to penetrate your system and exfiltrate your data? Pinpoint vulnerabilities, take action and build stronger cyber defenses with KnowBe4’s Breach Simulator “BreachSim.” Based on techniques outlined in the MITRE Att&CK framework, BreachSim launches 12+ simulated scenarios to uncover the stark reality of what happens when employees unknowingly fall for an attack.

BreachSim LogoHow BreachSim works:

  • 100% harmless simulation of real breach and data exfiltration attacks
  • Provides secure .txt, .doc, and .bmp test files for the simulation
  • Tests 12+ realistic data exfiltration scenarios following the MITRE Att&CK framework
  • Just download the installer, upload the secure test files, and run

Results in a few minutes!

Try Now

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/free-tools/breach-simulator



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews