Hackers spread a virus disguised as a Chrome update.

Hackers launched a virus disguised as a Chrome update
Uzbekistan, Tashkent – Podrobno.uz News Agency
Android device users in more than 26 countries have fallen victim to the DragonDoll spyware. It disguises itself as an urgent Google Chrome update and, once installed, gains extensive access to smartphone data, including instant messaging, SMS messages, calls, contacts, and user-entered data.
The campaign was discovered by Positive Technologies specialists. Over the course of two months, they discovered approximately 150 malware samples. The attack begins with a redirect to a fake website mimicking a Chrome page prompting the user to install the update. The app then requests access to Android's accessibility features. After receiving permission, DragonDoll installs a spyware module, allowing attackers to remotely control the device.
The malware is capable of taking screenshots, monitoring keystrokes, reading and deleting SMS messages, making calls, managing contacts, and displaying fake windows over legitimate apps to intercept passwords and PINs. Additionally, DragonDoll collects data from Telegram, WhatsApp, and Signal, including chat lists, contacts, and message content, and sends the collected information to the attackers' server.
According to Positive Technologies, DragonDoll was first discovered in the spring during an investigation into an attack on users in Saudi Arabia. A GitHub account was later discovered, which was used to distribute malware updates from March to May. More than 30 language versions were prepared for the fake websites, including Russian, Ukrainian, Chinese, Korean, and Arabic.
Experts warn that DragonDoll does not exploit Android vulnerabilities, but rather abuses the standard accessibility features. Users are advised to install Chrome and other app updates only from official stores or developer websites and avoid clicking on links to "urgent updates" from ads, messages, and pop-ups.

