Tashkent, Uzbekistan – AN Podrobno.uz. Android users in more than 26 countries have been targeted by a spyware campaign dubbed DragonDoll. The malware is distributed disguised as an urgent Google Chrome update and, once installed, can gain extensive access to a smartphone, including messenger conversations, SMS, calls, contacts, and user-entered data.
The campaign was uncovered by researchers at Positive Technologies. Over two months, they identified around 150 samples of the malicious program. The attack begins with a visit to a fake website designed to mimic a Chrome page: the user is prompted to install an update, after which the app requests access to Android's accessibility features. Once granted, DragonDoll installs a spy module and allows attackers to remotely control the device.
The malware can take screenshots, track keystrokes, read and delete SMS, make calls, work with contacts, and overlay fake windows on top of legitimate apps to intercept passwords and PIN codes. Additionally, DragonDoll collects data from Telegram, WhatsApp, and Signal, including chat lists, contacts, and message content, sending the harvested information to the attackers' server.
According to Positive Technologies, researchers first discovered DragonDoll in the spring while investigating an attack on users in Saudi Arabia. Later, they found a GitHub account through which updates of the malware were distributed from March to May. More than 30 language versions of the fake sites were prepared, including Russian, Ukrainian, Chinese, Korean, and Arabic.
Experts warn that DragonDoll does not exploit an Android vulnerability but abuses the legitimate accessibility feature. Users are advised to install updates for Chrome and other apps only through official stores or developers' websites, and to avoid clicking on links to "urgent updates" from ads, messages, or pop-ups.
Source: podrobno.uz