ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

PIN-Stealing Android Malware

mediumMalwareimportance 30
Full article117 words · extracted from schneier.com · click to collapse

This is an old piece of malware—the Chameleon Android banking Trojan—that now disables biometric authentication in order to steal the PIN:

The second notable new feature is the ability to interrupt biometric operations on the device, like fingerprint and face unlock, by using the Accessibility service to force a fallback to PIN or password authentication.

The malware captures any PINs and passwords the victim enters to unlock their device and can later use them to unlock the device at will to perform malicious activities hidden from view.

Tags: Android, banking, biometrics, malware, PINs

Posted on January 9, 2024 at 7:03 AM5 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2024/01/pin-stealing-android-malware.html