DragonDoll spyware hits Android users in 26 countries — here's how to stay safe

Android users in over 26 countries, including Russia, have been targeted by a spyware program called DragonDoll, which disguises itself as a Google Chrome update. The warning comes from Igor Bederov, General Director of the Internet Search company, in an interview with Komsomolskaya Pravda radio.
Bederov explained that attackers use DragonDoll for covert data collection. The malware is primarily designed for Android and can steal chat messages, log keystrokes, and overlay fake windows on top of other apps, including banking applications. The program infiltrates devices by posing as a browser update downloaded from unofficial sources.
The most effective way to protect a smartphone from DragonDoll, according to Bederov, is to install software exclusively from official app stores and trusted websites. This simple precaution prevents the malware from ever reaching the device.
If DragonDoll has already infected a smartphone, the expert advises taking immediate action. First, disconnect the device from the network to stop further data transmission. Then, perform a factory reset to remove most spyware samples—though Bederov warned that this method is not always effective. After resetting, users should change passwords for their most critical accounts, enable two-factor authentication, and, where possible, set up an additional cloud password for extra security.
Bederov emphasized that while factory resets can eliminate many threats, some persistent malware strains may survive, making additional security measures essential. Earlier, expert Borisov discussed how AI agents can spiral out of control.

