GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
ID: df431f94-515b-5e28-8663-62e0f531726b
STIX ID: report--df431f94-515b-5e28-8663-62e0f531726b
Feed Name: Threat Intelligence
The report details PROMPTSPY, an AI-augmented Android backdoor that can capture biometric gestures, block uninstallation via overlay-based touch interception, dynamically update C2 components (including LLM API keys and VNC relays), and be relaunchable via Firebase Cloud Messaging; it also highlights GTIG's broader findings of adversaries leveraging LLMs and agentic frameworks for high-fidelity reconnaissance, automated vulnerability discovery, and AI-supported information operations across multiple nation-aligned actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
