Chameleon Android malware can turn off fingerprint unlock to steal your pin

Be careful out there.
By Tim Marcin  on 
a finger over a fingerpint unlock on a screen
Be careful out there. Credit: Photo by Thomas Trutschel/Photothek via Getty Images

Sure, your fingerprint is one of a kind, but it might not keep your personal information safe any longer. That's because a new version of the Chameleon Android malware reportedly allows bad actors to bypass your fingerprint feature to steal your PIN.

According to researchers with ThreatFabric, the malware effectively tricks people into turning on accessibility services, which then allows attackers to change the phone from a biometric to a PIN lock. It does this, according to Bleeping Computer, by posing as legitimate Android apps and then displaying an HTML page that asks potential victims to turn on accessibility settings. This allows attackers to bypass protections, including fingerprint unlock. Then, when a victim uses the PIN to log-in instead of a fingerprint, the attackers are able to steal that PIN or any password.

People should be careful to make sure if they use an app, especially a banking app, that it is legitimate.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

"These enhancements elevate the sophistication and adaptability of the new Chameleon variant, making it a more potent threat in the ever-evolving landscape of mobile banking trojans," ThreatFabric said.

Bleeping Computer noticed the primary distribution method for the malware was Android package files (APKs) from unofficial sources.

So be careful out there. Even your unique fingerprint might not be enough to protect you.

Topics Android Privacy

Mashable Image
Tim Marcin

Tim Marcin is a culture reporter at Mashable, where he writes about food, fitness, weird stuff on the internet, and, well, just about anything else. You can find him posting endlessly about Buffalo wings on Twitter at @timmarcin.


Recommended For You
Move over LastPass! Apple announces new password manager at WWDC 2024
MacBook showing Passwords app


This is likely the biggest password leak ever: nearly 10 billion credentials exposed
Login screen

Score today's best unlocked Samsung phone deal before it's gone
Unlocked Samsung Galaxy phone on an abstract background

FCC wants to force carriers to unlock phones for consumers
Woman on smartphone

Trending on Mashable
NYT Connections today: See hints and answers for July 11
A phone displaying the New York Times game 'Connections.'

'Wordle' today: Here's the answer hints for July 11
a phone displaying Wordle


Webb telescope may have just revealed an alien world with air
A super-Earth orbiting a red dwarf star

NYT's The Mini crossword answers for July 11
Closeup view of crossword puzzle clues
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!