PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence
ID: 3208910e-5246-5664-8bbc-1dc8d9be2e44
STIX ID: report--3208910e-5246-5664-8bbc-1dc8d9be2e44
Feed Name: The Hacker News
ESET researchers uncovered PromptSpy, an Android malware that uniquely uses Google’s Gemini generative AI to analyze on‑screen UI dumps and return JSON instructions to automate taps and other interactions via accessibility services, enabling persistent pinning in recent apps. PromptSpy deploys a built‑in VNC module for remote access, captures lockscreen PINs/passwords, screenshots and screen recordings, prevents uninstallation via invisible overlays, retrieves a Gemini API key from its C2 (54.67.2.84), and is distributed via malicious websites targeting users in Argentina.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
