7 Sources
[1]
This Android Malware Connects to Google Gemini for Tips on Hacking Targets
Security researchers have uncovered an Android malware that connects to Google's Gemini chatbot to help it persist on an infected device. The malware appears to be targeting users in Argentina, and there are signs that a hacker in China developed its code, according to antivirus provider ESET. "We
[2]
Android malware taps Gemini to navigate infected devices
Cybersecurity researchers say they've spotted the first Android malware strain that uses generative AI to improve performance once installed. But it may be only a proof of concept. ESET calls it PromptSpy, malware whose primary goal is to deploy a VNC module that hands hackers remote control of
[3]
PromptSpy is the first Android malware to use generative AI at runtime
Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google's Gemini model to adapt its persistence across different devices. In a report today, ESET researcher Lukas Stefanko explains how a new Android malware family named "PromptSpy" is
[4]
PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence
Cybersecurity researchers have discovered what they say is the first Android malware that abuses Gemini, Google's generative artificial intelligence (AI) chatbot, as part of its execution flow and achieves persistence. The malware has been codenamed PromptSpy by ESET. The malware is equipped to
[5]
Android malware is now using Google's own Gemini AI to adapt in real time
It's been a worrying week on the Android malware front. On Tuesday, we learned of tablets shipping with hidden malware already embedded in their firmware. Now, researchers say they've spotted something arguably more futuristic: Android malware that uses Google's own Gemini AI model during
[6]
New Android malware uses Gemini AI to learn how to run on specific devices
Joe Fedewa has been writing about technology for over a decade. Android and the rest of the Google ecosystem have been a focus for years, as well as reviewing devices, hosting podcasts, filming videos, and writing tutorials. Joe loves all things technology and is also an avid DIYer and food
[7]
PromptSpy malware uses AI tools and Gemini to hijack Android devices
Chinese-developed PromptSpy malware exploits Gemini AI to hack Android devices * PromptSpy malware uses Gemini to automate its persistence * The malware blocks removal through an AI-guided interface control * Gemini interprets screen data and returns actionable gestures Security experts have
Share
Copy Link
Security researchers at ESET have discovered PromptSpy, the first known Android malware using generative AI during execution. The malware leverages Google's Gemini chatbot to interpret device interfaces and maintain persistence, while deploying a VNC module for remote access. Targeting users in Argentina through fake banking sites, PromptSpy demonstrates how threat actors are integrating AI to make malware more adaptive and difficult to remove.
Security researchers at ESET have uncovered PromptSpy, marking a significant shift in how Android malware operates. This strain represents the first known case of malware using generative AI during its execution flow, specifically leveraging Google's Gemini chatbot to help it persist on infected devices
1
. According to ESET researcher Lukas Stefanko, the malware sends predefined prompts to Gemini's API to interpret the user interface on infected devices and receive step-by-step instructions1
. While the Gemini component represents a relatively small portion of PromptSpy's overall capabilities, it performs a critical function that could expand the threat landscape significantly.
Source: How-To Geek
The malware's use of Gemini AI centers on a specific persistence mechanism: keeping the malicious app pinned in the recent apps list. PromptSpy sends Google's Gemini model a natural language prompt along with an XML dump of the current screen, including visible UI elements, text labels, class types, and screen coordinates
3
. Gemini then responds with JSON-formatted instructions describing what action to take and where to perform it on the device3
. The malware executes these actions through Android's Accessibility Service, retrieves the updated screen state, and sends it back to Gemini in a loop until the AI confirms successful app locking3
. This approach allows the malware to dynamically adapt its behavior across different devices, layouts, and OS versions—something traditional Android malware struggles with when relying on hardcoded taps and coordinates2
.
Source: Android Authority
While the AI-powered persistence is novel, PromptSpy's primary goal is deploying a VNC module that grants threat actors complete remote access and control over infected devices
4
. Once Accessibility Service permissions are granted, the malware operators can see everything happening on the device and perform taps, swipes, gestures, and text input as though physically holding the phone1
. The spyware can intercept lockscreen PINs and passwords, capture the pattern unlock screen as video, record screen activity, take screenshots on demand, and gather comprehensive device information3
. Communication with a hard-coded command-and-control server at 54.67.2[.]84 occurs via the VNC protocol4
.
Source: Hacker News
PromptSpy employs sophisticated anti-uninstall techniques to prevent removal. The malware overlays transparent, invisible rectangles over specific screen areas when users attempt to uninstall the app or disable Accessibility permissions
3
. These invisible overlays block taps on uninstall and force stop functions, making standard removal impossible1
. According to ESET, the only way victims can remove PromptSpy is by rebooting the device into Safe Mode, where third-party apps are disabled and can be uninstalled normally1
.ESET traced the malware to a phishing site at m-mgarg[.]com, which delivered PromptSpy through the related domain mgardownload[.]com
1
. Both domains were found offline during the investigation, but cached versions revealed they impersonated the JPMorgan Chase Argentina banking brand2
. The malware uses similar branding, with the app name MorganArg and an icon inspired by Chase Bank, suggesting regional targeting focused on Argentina1
. ESET discovered PromptSpy after samples were uploaded from Argentina to VirusTotal in January 20261
. Analysis of the code reveals Chinese language strings, suggesting a hacker from China developed it, though the campaign appears financially motivated rather than state-sponsored4
.Related Stories
Whether PromptSpy represents an active threat or remains a proof of concept is unclear. ESET told BleepingComputer it hasn't observed the malware or its dropper in its telemetry, which could indicate both are only proofs of concept
3
. However, the existence of dedicated distribution domains and a fake bank website suggests the malware may have been used in actual attacks3
. The malware was never found on the Google Play Store, and as an App Defense Alliance partner, ESET shared its findings with Google1
. Android users are automatically protected against known versions through Google Play Protect, which is enabled by default on devices with Google Play Services1
.PromptSpy joins a growing list of threats incorporating generative AI into their operations. In November 2025, Google warned about Windows-based malware strains dubbed Promptflux and Promptsteal that also connect to generative AI models to execute instructions
1
. Anthropic recently discovered hackers using its Claude AI chatbot to plan large-scale data extortion campaigns and develop ransomware1
. The finding demonstrates how threat actors are incorporating AI tools to automate actions that would be more challenging with conventional approaches, making malware far more dynamic and capable of real-time decision-making2
. For Android users, this evolution means watching for suspicious permission requests, avoiding sideloaded apps from unknown sources, and staying alert to phishing attempts impersonating legitimate banking institutions.Summarized by
Navi
[2]
[3]
[5]
05 Nov 2025•Technology

31 Jan 2025•Technology

07 Aug 2025•Technology
