DragonEgg

Aliases: LightSpy

First seen
2020-02-01 00:00:00
Malware type
spyware, trojan
Family
Malware family
Profile updated
2026-07-07 14:05:48

Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:hk country_code:tw country_code:cn

Context

DragonEgg is the Android variant of the LightSpy malware family, known for its espionage capabilities. It specifically targets users in the Hong Kong, Taiwan, and China regions.

Detection coverage

  • 2 YARA rules

Detection rules

  • VOLEXITY_Apt_Malware_Win_Lightspy_Orchestrator_Decoded_Core (yara-rule)
  • VOLEXITY_Apt_Malware_Win_Lightspy_Orchestrator_Decoded_C2_Strings (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Dragonegg (report)
  • threatfabric.com — Lightspy Mapt Mobile Payment System Attack (report)
  • lookout.com — Wyrmspy Dragonegg Surveillanceware Apt41 (report)

External references