DragonDoll Android Spyware Disguised as a Google Chrome Update

· Original article ↗

Summary

Researchers uncovered DragonDoll, a previously undocumented Android spyware family distributed through phishing pages posing as Chrome updates. It can remotely control devices, steal messages and collect extensive device data.

Key points

  • DragonDoll was discovered in spring 2026 in an Android APK named Chrome.apk. Phishing sites imitated Chrome update pages to persuade users to download it.
  • The infection chain uses a dropper and native libraries, with obfuscation and checks for debugging tools. The fake update and permission prompts are localized for users in multiple regions.
  • The spyware abuses Accessibility Services to monitor input and screen activity, control devices, capture screenshots, and collect contacts, SMS, notifications, and messenger data.
  • Operators can remotely control infected devices through VNC and accessibility-based interfaces, deploy overlays that capture entered data, and issue commands including SMS and call actions.
  • DragonDoll sends device information and collected data to command-and-control infrastructure using AES encryption, with RSA used to protect the session key. The analyzed samples used channelzones[.]co.
  • Researchers identified versions 9.3 and 9.4 and around 150 samples associated with an operator GitHub account. Distribution sites included datewithmealways[.]site and datewithmealways[.]online.

Article Details

Attack Vectors
  • Phishing sites masqueraded as Google Chrome update pages and prompted users to download the DragonDoll APK.
  • The initial APK presented a localized browser-update lure while installing a second APK from its resources. A native-library loading chain decrypted and launched the spyware payload.
  • DragonDoll requested Accessibility access under the guise of a Chrome update, then used it to observe user actions, extract on-screen data and remotely control the device.
  • The spyware could display application overlays and send user-entered data to its operators. PT ESC assessed that this capability was likely intended to impersonate banking applications and other login forms.
Defensive Notes
  • Treat browser-update prompts on unfamiliar sites that download an APK or request Accessibility access as suspicious.
  • The APK's modified ZIP header flags can obstruct extraction with standard archive tools; PT ESC corrected the flags before analysis.
  • The dropper checked for debugging artifacts and network connectivity, and could fail to decrypt its payload when those checks were not satisfied.
  • The source provides no specific remediation procedure.

Indicators of compromise

TypeIndicatorContext
DOMAINchannelzones[.]coC2 address reported in the configurations of the additional DragonDoll samples.
DOMAINdatewithmealways[.]onlineAdditional DragonDoll distribution address identified through shared network characteristics.
DOMAINdatewithmealways[.]sitePhishing site used to distribute DragonDoll through a fake Chrome update.
DOMAINdigitaladstracking[.]comAdditional DragonDoll distribution address identified through shared network characteristics.
EMAILkesmantes52@outlook[.]comEmail address the operators used to register the GitHub account associated with DragonDoll sample uploads.

MITRE ATT&CK

Malware

Products

Tools

Countries

Related Articles