logo

PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence

ID: 3208910e-5246-5664-8bbc-1dc8d9be2e44

STIX ID: report--3208910e-5246-5664-8bbc-1dc8d9be2e44

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-02-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

ESET researchers uncovered PromptSpy, an Android malware that uniquely uses Google’s Gemini generative AI to analyze on‑screen UI dumps and return JSON instructions to automate taps and other interactions via accessibility services, enabling persistent pinning in recent apps. PromptSpy deploys a built‑in VNC module for remote access, captures lockscreen PINs/passwords, screenshots and screen recordings, prevents uninstallation via invisible overlays, retrieves a Gemini API key from its C2 (54.67.2.84), and is distributed via malicious websites targeting users in Argentina.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.