FB pixel

Malware variant won’t compromise mobile biometrics, but it will neuter the code

Malware variant won’t compromise mobile biometrics, but it will neuter the code
 

Biometrics security on mobile devices is great unless it’s not turned on. Or if it gets turned off.

Researchers with a Dutch computer services firm have identified a variant of a known banking trojan that forces a device to switch from biometric authentication to PIN authentication. ThreatFabric says the malware can then unlock the device.

ThreatFabric says in a new report that the Android-specific Chameleon banking-focused trojan became a security problem in January. Chameleon is doing the most damage right now in Australia (where it specifically focuses on the nation’s tax office) and Poland.

It has been distributed on phishing pages doctored to look like legitimate apps. The new variant is distributed on the Zombinder platform on which criminals bind malware to Android apps.

The ability to sideline biometric security is new in the update. ThreatFabric’s report details how the hack works.

Biometric identifiers are untouched in this variant.

Nonetheless, the new Chameleon variant is not good news for the mobile biometric security market and raises the question, can biometric systems be created with their own defenses against being leapfrogged?

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

OCR Studio expands KYC fraud detection for AI-generated identity documents

Fake documents made with the help of generative AI are becoming increasingly more convincing. Document analysis and data extraction software…

 

ID4Africa speakers urge legal identity inclusion for refugees, stateless persons

African governments must accelerate efforts to provide legal and digital identity to refugees and stateless populations, according to speakers at…

 

Biometrics lawyer Dan Saeedi talks BIPA on Biometric Update Podcast

Dan Saeedi is a BIPA buster. The renowned Chicago attorney, CIPP/US,a partner and team co-lead of the biometric privacy team…

 

World Bank, African DPAs outline formula for trusted digital identity, DPI

Trust has moved steadily to the center of the conversation around digital public infrastructure and identity at ID4Africa, and the…

 

UK watchdog warns of legal risks as London police deploy LFR at protest

London’s Metropolitan Police will deploy live facial recognition (LFR) technology at a protest for the first time this weekend, prompting…

 

Age assurance debate arrives in Bangladesh

The dominos continue to fall in the game of global online safety legislation targeting social media platforms. Bangladesh is weighing…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events