Cybersecurity researchers have identified the first malware for Android that uses generative artificial intelligence, called PromptSpy.
This malicious program, which leverages Google’s Gemini technology, has the ability to capture data from the lock screen, block uninstallation attempts, and collect device information, in addition to taking screenshots and recording activity in video.
Do not download anything unsafe
PromptSpy is distributed through a dedicated website and has never been available on Google Play, suggesting that this malware campaign is targeted at users in Argentina. According to the analysis, there is evidence pointing to its development originating from a Chinese-speaking environment, as simplified Chinese debugging strings have been found.
The operation of PromptSpy is based on Gemini, which allows the malware to analyze the current screen and provides detailed instructions to ensure that the malicious application remains active in the recent list. This is achieved by using accessibility services, which forces users to restart the device in safe mode to uninstall the program. Interaction is done through a command and control server, giving attackers remote access to the victim’s device.

ESET researchers, who made the discovery, point out that PromptSpy represents a significant evolution of Android malware, using generative AI that allows it to adapt to different devices and operating system versions. This approach not only facilitates a more dynamic interaction but also makes it more complicated for users to eradicate it.
It has been indicated that the tactics employed suggest a possible financial objective on the part of the threat actors, highlighting the increasing sophistication of cyber attacks in the mobile space.


