✅ Fake Chrome update delivers DragonDoll spyware across 26 countries
A malicious update disguised as Google Chrome has infected Android devices in 26 countries, giving attackers near-total control over victims' phones.
The malware, called DragonDoll, uses "special functions" to bypass security measures and steal sensitive data from encrypted messaging apps like Telegram, WhatsApp, and Signal.
🦠 How the infection works
The attack relies on social engineering, tricking users into installing a fake version of the browser. Once installed, DragonDoll doesn't just steal files. It watches screen activity in real-time, intercepts incoming calls, and captures PINs and passwords as people type them. Most worryingly, it targets end-to-end encrypted apps by reading notifications and screen overlays, essentially bypassing the privacy protections users count on for secure chats.
⚡️ Scope and impact
The campaign has spread fast across 26 nations. The sophistication behind DragonDoll points to a well-funded group behind it, possibly state-sponsored or part of a major cybercrime network. Being able to read Signal messages, a platform known for rock-solid security, shows how serious this breach is. The attack happens at the device level, not by breaking the encryption itself.
😊 Follow us to stay informed about the latest threats and protect yourself.
#CyberSecurity #AndroidSafety #DragonDoll #PrivacyMatters #SpywareAlert
@PrivacyNotACrime 🗽 ⌨️ Chat
A malicious update disguised as Google Chrome has infected Android devices in 26 countries, giving attackers near-total control over victims' phones.
The malware, called DragonDoll, uses "special functions" to bypass security measures and steal sensitive data from encrypted messaging apps like Telegram, WhatsApp, and Signal.
🦠 How the infection works
The attack relies on social engineering, tricking users into installing a fake version of the browser. Once installed, DragonDoll doesn't just steal files. It watches screen activity in real-time, intercepts incoming calls, and captures PINs and passwords as people type them. Most worryingly, it targets end-to-end encrypted apps by reading notifications and screen overlays, essentially bypassing the privacy protections users count on for secure chats.
⚡️ Scope and impact
The campaign has spread fast across 26 nations. The sophistication behind DragonDoll points to a well-funded group behind it, possibly state-sponsored or part of a major cybercrime network. Being able to read Signal messages, a platform known for rock-solid security, shows how serious this breach is. The attack happens at the device level, not by breaking the encryption itself.
😊 Follow us to stay informed about the latest threats and protect yourself.
#CyberSecurity #AndroidSafety #DragonDoll #PrivacyMatters #SpywareAlert
@PrivacyNotACrime 🗽 ⌨️ Chat