Chameleon Android malware disables fingerprint unlock feature to steal your PIN

This super dangerous Android malware has returned to target US shoppers

The dreaded Chameleon Android malware has been upgraded to give attackers the ability to disable the fingerprint unlock feature and steal people's PINs, according to cybersecurity researchers at ThreatFabric.

According to the researchers, Chameleon is similar to other banking malware that abuses the Android Accessibility Service to steal sensitive information from endpoints and perform overlay attacks. This new version comes with two notable changes: the ability to enable Device Takeover (DTO) fraud and the ability to switch the lock screen from biometrics to PIN.