NewsPositive Technologies: hackers distribute Android spyware in more than 26 countries
News

Positive Technologies: hackers distribute Android spyware in more than 26 countries

Android users in more than 26 countries have been targeted by a new spyware app called DragonDoll, which masquerades as a Google Chrome browser update. The large-scale distribution campaign was uncovered by researchers from the Threat Intelligence Department at the Positive Technologies Expert Security Center (PT ESC). Over a two-month period, they identified roughly 150 malware samples. DragonDoll gives attackers near-complete control over an infected device and steals sensitive data, including conversations from messaging apps.

The infection chain begins the same way in every observed case. An Android user browsing with Google Chrome lands on a fake site designed to look like an official browser page. The site warns that an critical update is required. When the user clicks the update button, a malicious application is downloaded to the device. The app then asks the user to enable Accessibility Services—a legitimate Android feature intended to help users with visual impairments, but frequently abused by malware to gain broad control over a device. After receiving these permissions, DragonDoll installs its final spyware module on the device in several stages. This payload is heavily protected against reverse engineering.

After installation, the attackers can monitor activity on the infected smartphone in real time and control it remotely. DragonDoll can turn the screen on and off, log screen taps, read, send, and delete SMS messages, make phone calls and erase call history, add and remove contacts, and take screenshots. It can also silently display fake overlay windows over legitimate apps and intercept user-entered data. This allows the attackers to steal passwords, PIN codes, and other sensitive data.

The spyware focuses heavily on messaging apps. DragonDoll targets Telegram, WhatsApp,1 and Signal. By abusing the same Accessibility Services feature, it reads chat lists, contacts, message text, and timestamps directly from the screen. For Telegram, the malware includes an additional mechanism for intercepting the content of pop-up notifications. In other apps, including Viber, DragonDoll uses a simpler collection method: it copies whatever text is visible on the screen. All stolen data is encrypted and sent to the attackers' command-and-control server, which is hosted in Russia.

PT ESC researchers first detected the malware in spring 2026 while investigating an attack against users in Saudi Arabia. Further analysis led them to a GitHub account used to update the malware between March and May 2026. Around 150 DragonDoll samples appeared there during that period. A link from the account led to a network of fake Google Chrome "update" sites whose content changed based on the victim's language. In total, the attackers prepared more than 30 localized versions, including Russian, Ukrainian, Chinese, Korean, and Arabic. Researchers have not yet identified how links to these phishing sites were initially distributed.

1 WhatsApp is a product of Meta, which has been designated extremist and banned in Russia.

"DragonDoll does not exploit a software vulnerability. Instead, it abuses a legitimate Android feature that attackers often target because of the extensive permissions it provides. Users should be cautious if a newly installed app asks for Accessibility Services access without a clear reason. This is one of the most common tactics used by spyware. Browsers and other apps should be updated only through official stores, such as Google Play, or from the developer's official website. Users should avoid links to critical "updates" received through messages, ads, or pop-up windows."

Researchers from the Threat Intelligence Department at the Positive Technologies Expert Security Center