Android users targeted by new DragonDoll spyware
Translated from Russian, summarized and contextualized by DistantNews.
At a glance
- Android users in over 26 countries, including Russia, are targeted by a new spyware called DragonDoll.
- The malware spreads through fake Google Chrome update pages, gaining extensive control over infected smartphones.
- DragonDoll can steal passwords, read messages from apps like Telegram and WhatsApp, and send collected data to a Russian-hosted server.
Android smartphone users across more than 26 nations, including Russia, are facing a new wave of cyber threats from a sophisticated spyware dubbed DragonDoll. Security experts at Positive Technologies' expert center revealed the widespread nature of the attacks.
Users are lured to a fake Google Chrome page, where they are offered to download a supposed browser update.
Victims are lured to malicious websites designed to mimic legitimate Google Chrome update pages. There, they are prompted to download what appears to be a necessary browser update. Once installed and granted permissions, the DragonDoll spyware effectively hands over significant control of the user's smartphone to attackers.
After installation and obtaining the necessary permissions, the malicious program gives attackers almost full control over the smartphone.
The spyware is equipped with a range of invasive capabilities. It can record keystrokes, capture screenshots, access and read messages from popular messaging applications such as Telegram and WhatsApp, and even overlay fake login windows on top of legitimate apps to steal passwords and PIN codes. All the sensitive data collected is then transmitted to a server hosted within Russia.
DragonDoll can record keystrokes, take screenshots, read messages, and overlay fake windows over applications to steal passwords and PIN codes.
This malicious software was first identified earlier this spring by specialists from Positive Technologies' Threat Intelligence department while analyzing an attack targeting users in Saudi Arabia. Over the past two months, the security firm has documented approximately 150 distinct samples of this malware, underscoring the ongoing and evolving nature of the threat to Android users globally.
It collects data from Telegram, WhatsApp, and other messengers and sends it to a server hosted on Russian hosting.
Originally published by 24.kg in Russian. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.