Positive Technologies detects DragonDoll spyware hitting Android users in 26 countries
This digest was compiled by AI from multiple sources — links to the originals are below.

Positive Technologies detects a new spyware program, DragonDoll, hitting Android users in more than 26 countries, including Russia. The malware first appeared this spring during analysis of an attack on users in Saudi Arabia, and specialists have collected about 150 samples over two months. Victims lured by a fake Google Chrome update risk losing passwords, PIN codes, and data from Telegram and WhatsApp.
Key Facts
- Positive Technologies' Threat Intelligence department first detected DragonDoll this spring while analyzing an attack on users in Saudi Arabia.
- Over two months, the company's specialists found about 150 samples of the malware.
- DragonDoll spreads through a fake Google Chrome page offering a browser update.
- The malware can record keystrokes, take screenshots, read messages, and overlay fake windows to steal passwords and PIN codes.
- Data collected from Telegram, WhatsApp and other messengers is sent to a server on Russian hosting.
Infection Vector
The campaign has reached Android users in more than 26 countries, including Russia. Victims are lured to a fake Google Chrome page that offers what appears to be a browser update. After the victim installs the update and grants permissions, the malware gains almost full control over the smartphone. DragonDoll can overlay fake windows on top of legitimate applications to capture passwords and PIN codes.
Spyware Capabilities
DragonDoll records keystrokes, takes screenshots, and reads messages on infected devices across the 26-country campaign. It collects data from Telegram, WhatsApp and other messengers. Stolen information is sent to a server hosted on Russian hosting infrastructure. The malware can steal passwords and PIN codes by overlaying fake windows on legitimate apps.
Detection and Scale
Positive Technologies' Threat Intelligence department first detected DragonDoll this spring while analyzing an attack on users in Saudi Arabia. Over two months, specialists identified about 150 samples of the malware. RBK reported the findings citing the Positive Technologies expert security center.
1 source
Positive Technologies detects DragonDoll spyware hitting Android users in 26 countries



