Chameleon Android Banking Trojan Targets Users Through Fake CRM App
Researchers in cybersecurity have uncovered a new tactic used by the threat actors behind the Android banking trojan Chameleon, which targets Canadian users by pretending to be a customer relationship management (CRM) software.
Chameleon was observed posing as a CRM application and aimed at a global restaurant chain based in Canada, according to a technical analysis released on Monday by the Dutch security company ThreatFabric.
Targeting consumers in Canada and Europe, the advertisement was first seen in July 2024 and suggested that the company was expanding its victimology reach beyond Australia, Italy, Poland, and the United Kingdom.
The use of CRM-related themes by the malicious dropper programs that carry the malware suggests that business-to-consumer (B2C) workers and consum...

