Skip to main content
LiMP VPN
All news

DragonDoll Android Spy Hides Behind Chrome Update

DragonDoll Android Spy Hides Behind Chrome Update

In short: Positive Technologies researchers have uncovered a new Android spyware family called DragonDoll, which spreads via fake Chrome update websites and has been confirmed active in 26 countries, including Russia. Once installed, it reads Telegram, WhatsApp, and Signal conversations, intercepts passwords and PIN codes, and monitors the screen in real time. Installing apps exclusively from Google Play is the single most effective protection.

A New Spy App Found Across 26 Countries

In August 2026, the PT ESC team (Positive Technologies Expert Security Center) published findings from a months-long investigation into a new spyware family — DragonDoll. The first samples were discovered in spring 2026 during analysis of an attack targeting users in Saudi Arabia. Over the following two months, researchers identified approximately 150 unique malware samples and established that DragonDoll is active in at least 26 countries. Russia is among the targets: attackers prepared a fully localised Russian-language phishing page.

Two facts underline the campaign's scope. First, the attackers created more than 30 language versions of the fake website — including Russian, Ukrainian, Chinese, Korean, and Arabic. Second, the command-and-control server that receives stolen data is hosted at a Russian hosting provider — a tactic commonly used to complicate international infrastructure takedowns. For a look at how stolen credentials end up being monetised, see our piece on the billion-password infostealer leak.

How DragonDoll Reaches Your Device

The infection chain targets an ordinary user who is not thinking about security: attackers build a website that looks indistinguishable from the official Google Chrome download page. Victims typically arrive through search ads, messenger links, or emails urging them to "update Chrome for security reasons." The framing is deliberately ironic — the stated reason is protection, but the real outcome is the opposite.

On the fake page, users are prompted to download an APK file — an Android app package that bypasses Google Play. Android warns that the file comes from an unknown source, but DragonDoll includes step-by-step social engineering instructions designed to walk users past that warning. Technically, the malware does not exploit any Android vulnerability — instead, it abuses Accessibility Services, a legitimate feature built for users with disabilities, which grants an app broad access to the screen and other applications.

Once installed, DragonDoll requests the Accessibility Services permission. That permission becomes its core surveillance tool: the app can read screen content inside any open application, log keystrokes, and overlay invisible fake windows over real interfaces to harvest passwords as they are typed.

What DragonDoll Steals

The malware's capability list makes clear that DragonDoll is not opportunistic adware but a targeted personal surveillance tool:

  • Messenger conversations. DragonDoll reads chats in Telegram, WhatsApp, and Signal via overlay attacks. End-to-end encryption does not help — the malware operates at the device screen level, capturing messages after they are decrypted for display.
  • Passwords and PIN codes. Through interface spoofing, DragonDoll intercepts passwords and PIN codes as they are entered, including in banking apps.
  • Real-time screen recording. The app can record whatever is displayed on screen continuously.
  • SMS and call logs. DragonDoll intercepts incoming SMS messages — including two-factor authentication codes — and can view, edit, or delete call history and contacts.
  • Device control. The malware can turn the screen on and off and make phone calls without the owner's knowledge.

All stolen data is transmitted to the command server in encrypted form. PT ESC researchers note that DragonDoll uses multi-layer anti-analysis protection, making it significantly harder for standard antivirus software to detect.

Russia Among the Targets

The existence of a polished Russian-language phishing page indicates that DragonDoll's authors deliberately targeted Russian-speaking audiences. Russia was one of the first regions — after Saudi Arabia — where infections were confirmed in early 2026.

Our earlier report on Android banking trojans in Russia covered how threat actors adapt their toolkits specifically for Russian users. DragonDoll fits the same pattern, shifting focus from banking fraud to harvesting private communications and credentials. Those looking to reduce their online exposure can check out the LiMP VPN features page: encrypting your traffic hides browsing activity from your ISP and network owner. To be clear: a VPN protects data in transit — it does not stop spyware that is already installed on the device.

How to Protect Your Android Device

DragonDoll's infection chain can be broken at one of its very first steps. A few straightforward habits eliminate the threat:

  1. Install apps only from Google Play. Chrome updates arrive exclusively through the Play Store — the browser never asks you to download an APK from a website. Any page offering a Chrome APK download is fraud, without exception.
  2. Decline Accessibility Services requests from sideloaded apps. This feature is legitimate for screen readers and voice control, but no browser needs it. An APK-installed app requesting this permission is a red flag.
  3. Check the URL carefully. The real Chrome website does not offer standalone updates — the browser updates itself through the Play Store. Any page with a "Download APK" button is phishing.
  4. Enable Play Protect. Google Play Protect scans installed apps for malicious behaviour. Confirm it is active in your Play Store settings.
  5. Watch for unexpected permission requests. If an already-installed app suddenly asks for Accessibility Services, uninstall it immediately and run a full device scan with an antivirus such as Dr.Web or Kaspersky for Android.

For network-level privacy, a VPN adds a complementary protection layer. LiMP VPN encrypts your device traffic, preventing your ISP and network owner from seeing which sites you visit. This will not stop DragonDoll if it is already installed — but it reduces the risk of landing on a phishing page over an unsecured network and limits your browsing history exposure.

Sources

DragonDoll Android Spy Hides Behind Chrome Update | LiMP VPN