DragonEgg
Aliases: LightSpy
- First seen
- 2020-02-01 00:00:00
- Malware type
- spyware, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 14:05:48
Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:hk country_code:tw country_code:cn
Context
DragonEgg is the Android variant of the LightSpy malware family, known for its espionage capabilities. It specifically targets users in the Hong Kong, Taiwan, and China regions.
Detection coverage
- 2 YARA rules
Detection rules
- VOLEXITY_Apt_Malware_Win_Lightspy_Orchestrator_Decoded_Core (yara-rule)
- VOLEXITY_Apt_Malware_Win_Lightspy_Orchestrator_Decoded_C2_Strings (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Dragonegg (report)
- threatfabric.com — Lightspy Mapt Mobile Payment System Attack (report)
- lookout.com — Wyrmspy Dragonegg Surveillanceware Apt41 (report)