Android malware taps Gemini to navigate infected devices
ID: 9a69bcb1-2c57-5935-879a-ed5cf8c1ebc0
STIX ID: report--9a69bcb1-2c57-5935-879a-ed5cf8c1ebc0
Feed Name: The Register (Security)
Threat Score
ESET researchers identified PromptSpy, a proof-of-concept Android malware that uses generative AI (Google Gemini) to parse UI XML dumps and return JSON instructions to perform adaptive gestures, enabling persistence, VNC remote control, credential interception, screen recording, and uninstall prevention; samples were found on VirusTotal and linked to a likely distribution domain (now offline), but ESET has not observed active deployment in its telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
