DragonDoll Android Spyware Disguised as a Google Chrome Update

Summary
Researchers uncovered DragonDoll, a previously undocumented Android spyware family distributed through phishing pages posing as Chrome updates. It can remotely control devices, steal messages and collect extensive device data.
Key points
- DragonDoll was discovered in spring 2026 in an Android APK named Chrome.apk. Phishing sites imitated Chrome update pages to persuade users to download it.
- The infection chain uses a dropper and native libraries, with obfuscation and checks for debugging tools. The fake update and permission prompts are localized for users in multiple regions.
- The spyware abuses Accessibility Services to monitor input and screen activity, control devices, capture screenshots, and collect contacts, SMS, notifications, and messenger data.
- Operators can remotely control infected devices through VNC and accessibility-based interfaces, deploy overlays that capture entered data, and issue commands including SMS and call actions.
- DragonDoll sends device information and collected data to command-and-control infrastructure using AES encryption, with RSA used to protect the session key. The analyzed samples used channelzones[.]co.
- Researchers identified versions 9.3 and 9.4 and around 150 samples associated with an operator GitHub account. Distribution sites included datewithmealways[.]site and datewithmealways[.]online.
Article Details
- Attack Vectors
- Phishing sites masqueraded as Google Chrome update pages and prompted users to download the DragonDoll APK.
- The initial APK presented a localized browser-update lure while installing a second APK from its resources. A native-library loading chain decrypted and launched the spyware payload.
- DragonDoll requested Accessibility access under the guise of a Chrome update, then used it to observe user actions, extract on-screen data and remotely control the device.
- The spyware could display application overlays and send user-entered data to its operators. PT ESC assessed that this capability was likely intended to impersonate banking applications and other login forms.
- Defensive Notes
- Treat browser-update prompts on unfamiliar sites that download an APK or request Accessibility access as suspicious.
- The APK's modified ZIP header flags can obstruct extraction with standard archive tools; PT ESC corrected the flags before analysis.
- The dropper checked for debugging artifacts and network connectivity, and could fail to decrypt its payload when those checks were not satisfied.
- The source provides no specific remediation procedure.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | channelzones[.]co | C2 address reported in the configurations of the additional DragonDoll samples. |
| DOMAIN | datewithmealways[.]online | Additional DragonDoll distribution address identified through shared network characteristics. |
| DOMAIN | datewithmealways[.]site | Phishing site used to distribute DragonDoll through a fake Chrome update. |
| DOMAIN | digitaladstracking[.]com | Additional DragonDoll distribution address identified through shared network characteristics. |
kesmantes52@outlook[.]com | Email address the operators used to register the GitHub account associated with DragonDoll sample uploads. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe loading chain used tampered APK ZIP headers, LLVM-based obfuscation, encrypted strings and an encrypted payload to impede analysis.T1036 · MasqueradingThe malware impersonated a Google Chrome update, including in its lure screens and permission prompts.T1056.001 · KeyloggingDragonDoll intercepted user input through AccessibilityService and an overridden onKeyEvent method.T1056.002 · GUI Input CaptureDragonDoll could display application-replacing overlays and send user-entered data from them to the operators.T1074.001 · Local Data StagingDragonDoll stored collected notifications, SMS messages and operational results in a local SQLite database.T1113 · Screen CaptureDragonDoll used MediaProjectionService to capture screenshots.T1204.002 · Malicious FileThe fake Chrome update page prompted users to download the DragonDoll APK.T1573.001 · Symmetric CryptographyDragonDoll encrypted transmitted data with AES-256-CBC and exchanged the AES key using RSA-OAEP.T1622 · Debugger EvasionThe dropper checked for debugging artifacts, including Frida, and could fail to decrypt its payload when they were detected.
Malware
Products
AndroidWe discovered DragonDoll, a previously unknown multifunctional Android spyware family.GitHubnumber from Spain and Saudi Arabia. One file was originally downloaded from a link pointing to the GitHub repository nowayintheland.Google ChromeThe malware impersonates Google Chrome.SignalSignalTelegramTelegramViberFor Viber and all packages containing the substring messenger, DragonDoll uses a simple method named extractGenericMessagingContent. This method recursively walks through all incoming elements and extracts text fromWhatsAppFor WhatsApp, DragonDoll behaves similarly to its Signal logic. It uses known application ViewIDs to collect information about chats, contacts, and message content.
Tools
droidVNC-NGDragonDoll then initializes the VNC server. Its implementation is based on the open-source droidVNC-NG project, which provides remote access to an Android device without root privileges. The project consists of JavaFridaIt checks whether the sample is running under a debugger, including Frida or similar frameworks. If debugging artifacts are detected, the file is not decrypted correctly.
Countries
ChinaThe implant is adapted for attacks against users in multiple regions, including Russia, China, Korea, and several MENA countries.KoreaThe implant is adapted for attacks against users in multiple regions, including Russia, China, Korea, and several MENA countries.RussiaThe implant is adapted for attacks against users in multiple regions, including Russia, China, Korea, and several MENA countries.Saudi ArabiaTechnologies Expert Security Center (PT ESC) identified an unusual campaign targeting users in Saudi Arabia. The campaign used a previously unknown APK named Chrome.apk. The sample immediately attracted our