Перейти к содержанию

Android attacked by new spyware: DragonDoll masquerades as Chrome update

The malware gains almost complete control over the smartphone, stealing correspondence, passwords, and PIN codes

Android users in more than 26 countries, including Russia, are being attacked by new spyware called DragonDoll. It masquerades as a Google Chrome update: a person lands on a fake browser page, clicks the install button, and launches the malware themselves.

After gaining access to Android's accessibility features, the software installs the final spyware module. According to Positive Technologies, DragonDoll can remotely control the smartphone, turn the screen on and off, record keystrokes, take screenshots, and read displayed messages.

Separately, the program can overlay fake windows over real applications and intercept entered data — this way, attackers can obtain passwords and PIN codes. DragonDoll also reads chats and contacts in Telegram and WhatsApp, intercepts notifications, and in other applications, copies everything visible on the screen.

Over two months, specialists discovered about 150 samples of DragonDoll. The collected information is encrypted and sent to the attackers' server, hosted in Russia. PT warns: the infection begins precisely with a fake offer to update Chrome via a third-party website.

Read more on the topic: