Android users in more than 26 countries have been targeted by a new spyware app called DragonDoll, which masquerades as a Google Chrome browser update. The large-scale distribution campaign was uncovered by researchers from the Threat Intelligence Department at the Positive Technologies Expert Security Center (PT ESC). Over a two-month period, they identified roughly 150 malware samples. DragonDoll gives attackers near-complete control over an infected device and steals sensitive data, including conversations from messaging apps.
The infection chain begins the same way in every observed case. An Android user browsing with Google Chrome lands on a fake site designed to look like an official browser page. The site warns that an critical update is required. When the user clicks the update button, a malicious application is downloaded to the device. The app then asks the user to enable Accessibility Services—a legitimate Android feature intended to help users with visual impairments, but frequently abused by malware to gain broad control over a device. After receiving these permissions, DragonDoll installs its final spyware module on the device in several stages. This payload is heavily protected against reverse engineering.
After installation, the attackers can monitor activity on the infected smartphone in real time and control it remotely. DragonDoll can turn the screen on and off, log screen taps, read, send, and delete SMS messages, make phone calls and erase call history, add and remove contacts, and take screenshots. It can also silently display fake overlay windows over legitimate apps and intercept user-entered data. This allows the attackers to steal passwords, PIN codes, and other sensitive data.
