logo

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

ID: df431f94-515b-5e28-8663-62e0f531726b

STIX ID: report--df431f94-515b-5e28-8663-62e0f531726b

Feed Name: Threat Intelligence

Threat Score
72/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Google Threat Intelligence Group

...
...

The report details PROMPTSPY, an AI-augmented Android backdoor that can capture biometric gestures, block uninstallation via overlay-based touch interception, dynamically update C2 components (including LLM API keys and VNC relays), and be relaunchable via Firebase Cloud Messaging; it also highlights GTIG's broader findings of adversaries leveraging LLMs and agentic frameworks for high-fidelity reconnaissance, automated vulnerability discovery, and AI-supported information operations across multiple nation-aligned actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.