In short: On August 17, 2026, Positive Technologies warned of widespread distribution of DragonDoll, Android spyware disguised as a Google Chrome browser update. The malware steals conversations from Telegram, WhatsApp, and Viber, intercepts passwords, and takes screenshots. Positive Technologies confirmed infections across 26+ countries, including Russia.
What Happened
On August 17, 2026, Positive Technologies' Expert Security Center (PT ESC) published an analysis of an active DragonDoll campaign. Researchers first detected the malware in spring 2026 while investigating incidents in Saudi Arabia. Within two months, approximately 150 samples were documented — a scale suggesting a well-organized, ongoing operation. For an overview of how network encryption protects your data, see LiMP VPN features.
"DragonDoll gives attackers almost complete control over the victim's device and steals data, including messenger conversations," according to Positive Technologies' press service.
How DragonDoll Infects Android Devices
The infection chain exploits inattention. Victims are directed to a fake website that visually mimics the official Google Chrome page, where they are prompted to install a "critical browser update." Clicking the button downloads a malicious APK file instead of a legitimate update.
On first launch, DragonDoll requests Accessibility Service permissions — a critical step that grants the trojan access to the screen content and keyboard input of any installed application. The final spyware module is protected against reverse engineering, making detection by standard antivirus solutions difficult. A similar tactic was used by the RedHook trojan: see our coverage of the RedHook Android trojan.
What DragonDoll Steals
Once installed, the spyware intercepts a broad range of data:
- Messenger conversations. The trojan reads chat lists and contacts from Telegram and WhatsApp, and in Viber copies everything visible on screen.
- Push notifications. DragonDoll intercepts notification content from any app, including banking one-time passwords.
- Keystroke logging. All keystrokes — passwords, PINs, search queries — are recorded and sent to a command server.
- Screenshots. The malware captures screen images at arbitrary moments, recording banking interfaces, open documents, and private correspondence.
- Phishing overlays. The trojan displays fake credential entry forms over legitimate apps to harvest login data.
- Device management. Attackers can remotely turn the screen on or off, upload and download files, and control the device.
Russia Among 26+ Countries at Risk
Positive Technologies confirmed DragonDoll infections in Saudi Arabia, Russia, and more than 24 other countries. Approximately 150 documented samples in two months indicate the campaign is active and ongoing. Earlier research documented a related surge: see our coverage of the Android banking trojan surge in Russia.
All Android users who install applications from third-party sources are at risk — regardless of device model or OS version.
How to Protect Your Smartphone
- Only install apps from Google Play. Chrome updates inside the app or through the Play Store — any website with a download button is a phishing site.
- Do not grant Accessibility Service to unknown apps. A request for these permissions from an unfamiliar app is a reliable indicator of malware.
- Enable Google Play Protect. The built-in scanner periodically checks installed apps for malicious behavior.
- Keep Android updated. Security patches close vulnerabilities that attackers exploit.
- Encrypt your traffic. A VPN cannot block spyware that is already installed, but it encrypts your internet connection and protects data your device transmits — especially on public Wi-Fi. LiMP VPN supports WireGuard on Android and iOS.
