Chameleon Android malware can turn off fingerprint unlock to steal your pin

Be careful out there.
By Tim Marcin  on 
a finger over a fingerpint unlock on a screen
Be careful out there. Credit: Photo by Thomas Trutschel/Photothek via Getty Images

Sure, your fingerprint is one of a kind, but it might not keep your personal information safe any longer. That's because a new version of the Chameleon Android malware reportedly allows bad actors to bypass your fingerprint feature to steal your PIN.

According to researchers with ThreatFabric, the malware effectively tricks people into turning on accessibility services, which then allows attackers to change the phone from a biometric to a PIN lock. It does this, according to Bleeping Computer, by posing as legitimate Android apps and then displaying an HTML page that asks potential victims to turn on accessibility settings. This allows attackers to bypass protections, including fingerprint unlock. Then, when a victim uses the PIN to log-in instead of a fingerprint, the attackers are able to steal that PIN or any password.

People should be careful to make sure if they use an app, especially a banking app, that it is legitimate.

"These enhancements elevate the sophistication and adaptability of the new Chameleon variant, making it a more potent threat in the ever-evolving landscape of mobile banking trojans," ThreatFabric said.

Bleeping Computer noticed the primary distribution method for the malware was Android package files (APKs) from unofficial sources.

So be careful out there. Even your unique fingerprint might not be enough to protect you.

Topics Android Privacy

Mashable Image
Tim Marcin

Tim Marcin is a culture reporter at Mashable, where he writes about food, fitness, weird stuff on the internet, and, well, just about anything else. You can find him posting endlessly about Buffalo wings on Twitter at @timmarcin.


Recommended For You
Google Maps: A new time-saving feature is finally here
a Google Maps logo seen displayed on a smartphone screen

How to talk to a human at the IRS
Two women on the phone.

Best tax software deals 2024: File now to get your taxes out of the way early this year
By Jillian Anthony
A person works on their taxes with a calculator nearby.

Netflix's final '3 Body Problem' trailer promises 'they are coming'
Two people sit on a couch with a strange VR headset.

The best sexting apps for sending naughty messages
Messages on phone

Trending on Mashable
NYT Connections today: See hints and answers for March 9
A phone displaying the New York Times game 'Connections.'

Wordle today: Here's the answer and hints for March 9
a phone displaying Wordle

NYT Connections today: See hints and answers for March 8
A phone displaying the New York Times game 'Connections.'

21 of the best ChatGPT courses you can take online for free
ChatGPT on phone

Best hookup apps and dating sites to find casual sex with no strings attached
Cartoon graphic of a person on a dating app.
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!