DragonDoll spyware campaign puts Android users in 26 countries at risk
Android users in more than 26 countries are being warned about a new spyware campaign involving a malicious program known as DragonDoll, which security researchers say can give attackers extensive control over infected devices.
According to cybersecurity experts at Positive Technologies, the malware has been used to target Android smartphones and can collect sensitive information, including messages and other personal data. The campaign reportedly affects users in several countries, including Russia.
The infection begins with a deceptive website designed to resemble the official Google Chrome page. Victims are encouraged to download what appears to be a browser update, but the installation instead introduces the malicious software onto their smartphones.
Once installed, DragonDoll can provide attackers with broad access to the compromised device. Researchers say its capabilities include recording screen activity, capturing screenshots, monitoring user interactions and accessing messages and notifications.
The spyware can also collect information from popular messaging applications such as Telegram, WhatsApp and Viber. It may access contact lists and chat information while attempting to capture sensitive credentials, including passwords and PIN codes, through fraudulent interface windows.
Collected information is reportedly encrypted before being transmitted to servers controlled by the attackers, increasing the difficulty of detecting and analyzing the stolen data.
The campaign highlights a broader cybersecurity problem affecting Android users: malicious actors increasingly rely on fake software updates and impersonated websites to persuade victims to install malware themselves. Instead of exploiting a technical vulnerability directly, attackers often manipulate users into believing that a legitimate application needs an urgent update.
Security specialists recommend downloading applications and updates exclusively through official sources and avoiding installation files offered through unfamiliar websites, messages or unsolicited emails. Users should also be cautious of pages that request unusual permissions or pressure them to install software immediately.
The warning comes amid growing concerns about Android malware campaigns targeting personal information. Russian authorities previously warned about another malicious program known as Drama RAT, which was distributed through messaging services, text messages and emails under deceptive names such as tax documents and payment invoices.
The emergence of DragonDoll demonstrates how spyware campaigns continue to evolve, combining social engineering with extensive surveillance capabilities. For Android users, maintaining updated security software and verifying the legitimacy of websites before installing applications remain essential measures for reducing the risk of infection.
-
18:25
-
18:10
-
17:48
-
17:33
-
17:15
-
17:00
-
16:41
-
16:20
-
16:05
-
15:44
-
15:25
-
15:10
-
14:50
-
14:34
-
14:22
-
14:15
-
14:05
-
14:00
-
14:00
-
13:53
-
13:49
-
13:42
-
13:21
-
13:21
-
13:21
-
13:05
-
13:02
-
12:45
-
12:28
-
12:12
-
11:47
-
11:30
-
11:20
-
11:16
-
11:15
-
11:00
-
10:52
-
10:43
-
10:26
-
10:25
-
10:19
-
10:12
-
10:10
-
10:07
-
09:58
-
09:45
-
09:45
-
09:25
-
09:10
-
08:57
-
08:48
-
08:44
-
08:33
-
08:25
-
08:24
-
08:17
-
08:16
-
08:15
-
08:13
-
08:11
-
08:08
-
08:06
-
08:03
-
08:00
-
07:59
-
07:54
-
07:43
-
07:21
-
21:00
-
20:25
-
20:10
-
19:45
-
19:25
-
19:05
-
18:47