Researchers have identified a new Android malware family called PromptSpy, marking the first known case of malware using a generative AI model during runtime to guide its actions on infected devices. According to ESET researcher Lukas Stefanko, the malware leverages Google’s Gemini model to automate tasks that vary across Android manufacturers, making it more resilient and harder to remove.
The campaign began with an earlier variant named VNCSpy, which appeared on VirusTotal in January 2026, followed by more advanced PromptSpy samples uploaded in February. Unlike traditional malware that relies on static scripts, PromptSpy sends Gemini an XML dump of the device’s current screen and receives JSON instructions on how to lock or pin the app in the Recent Apps list. This technique helps the malware persist by preventing Android from terminating it during cleanup.
PromptSpy also functions as spyware, using a built-in VNC module to provide attackers full remote control when Accessibility permissions are granted. Capabilities include capturing screenshots, recording screen activity, intercepting lockscreen credentials, listing installed apps, and monitoring foreground applications.
To resist removal, the malware overlays invisible UI elements on uninstall or stop buttons, preventing users from disabling it. ESET has not yet observed active infections in telemetry, suggesting it may be a proof-of-concept, though distribution via spoofed banking websites and dedicated domains indicates possible real-world use.
The discovery highlights a shift toward AI-assisted malware that can dynamically adapt its behavior, signaling a growing threat as generative AI tools are increasingly integrated into cyberattack workflows.

















Comments