Android users in more than 26 countries, including Russia, have been hit by a new spyware program DragonDoll — it pretends to be a scheduled update of Google Chrome, and having gained access to the device, reads correspondence in Telegram, Viber and WhatsApp*, steals passwords and can turn on someone else’s screen as if it were her own.
An update that no one ordered
The story is as old as the smartphone itself: a user is scrolling through the Internet, comes across a page that is exactly like the official Chrome page, and sees a persistent offer to update, reports xrust. The only difference is that the site is fake, and instead of the latest version of the browser, DragonDoll lands on your phone.
The scheme works simply, but effectively. The program first asks for access to Android's accessibility features — the very feature that, according to the developers' plans, should help people with disabilities, but in practice has become a favorite loophole for malware. Having received permission, DragonDoll unfolds in several stages and finally installs a spy module that is specially protected from analysis by researchers. That is, the creators prepared in advance for the fact that their brainchild would be dissected in cybersecurity laboratories — and, apparently, they did not prepare in vain.
What the invisible program can do
The list of DragonDoll features reads like a technical specification for an ideal digital spy. The device is controlled remotely: hackers turn the victim’s screen on and off as if they were sitting behind her back. All clicks are recorded, screenshots are taken, and incoming messages are intercepted.
The trick with fake windows deserves special attention. DragonDoll can quietly overlay a fake interface on top of real applications — banking clients, mail, instant messengers — and thus collects passwords and PIN codes right at the moment they are entered. The victim enters numbers into what looks like the application's native interface, but in reality feeds the data to a completely different program.
Messengers are a different story. The program reads lists of chats and contacts in Telegram and WhatsApp* — the same one that belongs to the extremist Meta* recognized in Russia — and at the same time intercepts the contents of pop-up notifications in Telegram directly from the screen, without even entering the application itself. Viber is even more straightforward: the Trojan copies literally everything that is shown on the victim’s screen. There is no selectivity — the entire visual flow goes under the knife. What is collected is encrypted and goes to a server, which, remarkably, is hosted on Russian hosting — that is, hunters for other people’s secrets did not hesitate to rent infrastructure in the same place where their victims live.
From Saudi Arabia to Russian smartphones
We discovered DragonDoll not yesterday. Specialists from Positive Technologies' Threat Intelligence department first came across the malware back in the spring of 2026, while investigating an attack on users from Saudi Arabia. Since then, the coverage has expanded noticeably: in two months, experts collected about 150 samples of the program, and the geography of victims grew to more than 26 countries, including Russia.
Such a campaign spread across time and countries is not an accident or a one-time outing of enthusiasts. With a dozen samples and several months of observations, there is usually a team that methodically tests and refines the product, adapting it to new markets. DragonDoll, apparently, is just that — a commercial spy tool that simply reached the Russian audience with its standard set of functions.
Not the first call this summer
DragonDoll is not the only headache for Android owners this summer. In June 2026, the Ministry of Internal Affairs Directorate for Combating Illegal Use of ICT already warned about another malware — Drama RAT, which also gives attackers remote access, steals data and can manipulate banking applications, even completely blocking the device. The similarity of approaches — masquerading as legitimate software, relying on the special features of Android, banking sights — speaks more of a trend than a coincidence.
At the same time, the overall statistics do not look as dramatic as individual stories about the Trojans. According to the Ministry of Internal Affairs, from January to July 2026, the number of cybercrimes in Russia decreased by 30% year on year — from 371.4 thousand to 252.9 thousand cases. Measures like the Antifraud system, launched in 2025, have worked. But the decline in the overall figure does not negate the fact that individual campaigns like DragonDoll are becoming more sophisticated: mass fraud is on the decline, and targeted spy tools, on the contrary, are improving.
How not to become the next victim
The recipe for protection is banal to the point of indecency, but that is why it is worth repeating. You need to install applications and browser updates exclusively from official sources — Google Play or directly from a trusted developer’s website, and not via a link from a suspicious banner. Before downloading anything, you should carefully look at the site address: fakes usually differ from the original by one or two letters or a non-standard domain. And, perhaps, the main rule is not to give applications advanced permissions, including special features, unless you are one hundred percent sure why a particular program needs such a level of access to your phone.
Updating your browser is a routine and boring operation. This is why it works so well as a bait: no one expects a trick from the “Update” button. DragonDoll is betting on this routine and, judging by the geography of the attack, it is not making a mistake so far.
Xrust DragonDoll: a spy disguises itself as a Chrome update and gets into the correspondence of Russians
- Если Вам понравилась статья, рекомендуем почитать
- TickTick: как пользоваться планировщиком задач, привычками и Pomodoro
- DaisyDisk for Mac: How to Find Large Files and Free Up Space Safely







