logo

Android Malware Hijacks Google Gemini to Stay Hidden

ID: e3ae96b8-0da8-5e64-975a-5192dc701c43

STIX ID: report--e3ae96b8-0da8-5e64-975a-5192dc701c43

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-02-20

Date Updated: 2026-04-22

...
...

ESET researchers identified PromptSpy, an Android malware implant evolving from VNCSpy that uses Google’s Gemini generative AI plus Accessibility Services to automatically interact with device UIs and lock itself in the Recent Apps list for persistence; it provides VNC-based remote control to capture screens, intercept PINs/patterns, record gestures, and exfiltrate data, and was distributed via a banking-themed trojan (MorganArg) impersonating JPMorgan Argentina with IOCs including mgardownload.com / m-mgarg.com and C2 54.67.2.84.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.