This is the first malware for Android that uses generative AI

Cybersecurity researchers have identified the first malware for Android that uses generative artificial intelligence, called PromptSpy. This malicious program, which leverages Google’s Gemini technology, has the ability to capture data from the lock screen, block uninstallation attempts, and collect device information, in addition to taking screenshots and recording activity in video. Do not download anything unsafe PromptSpy is distributed through a dedicated website and has never been available on Google Play, suggesting that this malware campaign is designed for users in Argentina. According to the analysis, […]

Cybersecurity researchers have identified the first malware for Android that uses generative artificial intelligence, called PromptSpy.

This malicious program, which leverages Google’s Gemini technology, has the ability to capture data from the lock screen, block uninstallation attempts, and collect device information, in addition to taking screenshots and recording activity in video.

Do not download anything unsafe

PromptSpy is distributed through a dedicated website and has never been available on Google Play, suggesting that this malware campaign is targeted at users in Argentina. According to the analysis, there is evidence pointing to its development originating from a Chinese-speaking environment, as simplified Chinese debugging strings have been found.

The operation of PromptSpy is based on Gemini, which allows the malware to analyze the current screen and provides detailed instructions to ensure that the malicious application remains active in the recent list. This is achieved by using accessibility services, which forces users to restart the device in safe mode to uninstall the program. Interaction is done through a command and control server, giving attackers remote access to the victim’s device.

ESET researchers, who made the discovery, point out that PromptSpy represents a significant evolution of Android malware, using generative AI that allows it to adapt to different devices and operating system versions. This approach not only facilitates a more dynamic interaction but also makes it more complicated for users to eradicate it.

It has been indicated that the tactics employed suggest a possible financial objective on the part of the threat actors, highlighting the increasing sophistication of cyber attacks in the mobile space.

These new phishing tactics that take advantage of trust among senior executives

Recently, a sophisticated phishing attack has put companies on alert, especially those operating in the Middle East. Malicious actors managed to impersonate an ongoing email thread between high-level executives, using a phishing link that mimicked a Microsoft authentication form, demonstrating a clever execution of social engineering. The clever impersonation technique The attack began with a compromised sales manager account in a contracting company, allowing the insertion of a malicious message into a legitimate conversation. This tactic exploits trust […]

Recently, a sophisticated phishing attack has put companies on alert, especially those operating in the Middle East. Malicious actors managed to impersonate an ongoing email thread between high-level executives, using a phishing link that mimicked a Microsoft authentication form, demonstrating a clever execution of social engineering.

The Ingenious Identity Theft Technique

The attack began with a compromised sales manager account at a contracting company, allowing the insertion of a malicious message into a legitimate conversation. This tactic, which exploits trust and communication within organizations, has proven to be particularly effective, as attackers took advantage of genuine emails between employees to create an appearance of normalcy in their phishing emails.

Researchers have linked the incursion to an active campaign since December 2025, which has primarily targeted companies in the financial and energy sectors in the region. The investigation revealed the use of EvilProxy, a phishing tool that evades traditional detections, by introducing a proxy system that allows attackers to operate undetected.

This type of attack not only takes advantage of technical vulnerabilities but also crafts human workflows, making emails appear perfect, which makes them harder to detect by filtering systems like DMARC. As remote work becomes normalized and asynchronous approval processes become common, companies face an increased risk of compromises.

The importance of having adequate defense measures has grown significantly. Tools like ANY.RUN provide the ability to detect phishing behaviors in real-time, shortening response times to incidents and strengthening corporate cybersecurity.

The rise of AI-generated malware poses new threats to cybersecurity

Security researchers have warned of an alarming increase in the development of malware using artificial intelligence tools, marking a significant transition from the theoretical to the practical in cybercrime. This phenomenon has been documented by the cybersecurity firm Check Point Research, which has analyzed the activities of a well-known state-backed threat actor from North Korea, known as KONNI, which has been active for over a decade. The evolution of cyber threats Initially, KONNI’s focus was on politicians, diplomats, and academics, primarily in South Korea. However, in its latest campaign, […]

Security researchers have warned of an alarming increase in the development of malware using artificial intelligence tools, marking a significant transition from the theoretical realm to practical applications in cybercrime. This phenomenon has been documented by the cybersecurity firm Check Point Research, which has analyzed the activities of a well-known state-backed threat actor from North Korea, known as KONNI, which has been active for over a decade.

The evolution of cyber threats

Initially, KONNI’s focus was on politicians, diplomats, and academics, primarily in South Korea. However, in its latest campaign, the group has changed its strategy, targeting software developers, especially those related to blockchain and cryptocurrencies. The attackers have been using highly convincing phishing techniques to access cloud infrastructures, source code repositories, and blockchain credentials.

CPR researchers explain that those who have fallen into the trap have allowed the installation of an AI-generated backdoor in PowerShell, which has provided attackers with full access to the victims’ computers and the secrets stored on them. This use of AI-generated malware not only accelerates the development of new attacks but also allows for faster and more flexible customization of threats, thereby evading traditional signature-based detection methods.

In light of this new reality, cybersecurity professionals will need to adapt their approaches. There is an emphasis on the need to consider development environments as high-value targets and to strengthen prevention against phishing within collaboration and development workflows. Additionally, it is recommended to protect development infrastructures and the cloud with robust access controls and to use AI-driven threat prevention techniques to detect malware that is not visible in the early stages of an attack.

ChatGPT will have ads, although they said it was the last resort

OpenAI has announced that it will begin testing targeted ads in ChatGPT for a select group of users in the United States, a decision that represents a significant effort by the company to generate revenue. The introduction of this feature comes at a time when OpenAI is not expected to reach profitability for several years, highlighting the financial difficulties the company is currently facing. Generative (and promoted) AI OpenAI’s CEO, Sam Altman, had previously stated that advertising in ChatGPT would be a “last resort,” suggesting that the situation […]

OpenAI has announced that it will begin testing targeted ads in ChatGPT for a select group of users in the United States, a decision that represents a significant effort by the company to generate revenue. The introduction of this feature comes at a time when OpenAI is not expected to reach profitability for several years, highlighting the financial challenges the company is currently facing.

Generative (and promoted) AI

The CEO of OpenAI, Sam Altman, had previously stated that advertising on ChatGPT would be a “last resort”, suggesting that the company’s financial situation might be more complicated than initially thought. Despite his claims, the arrival of ads on the platform had been the subject of rumors for some time, indicating that the possibility of monetization has been on OpenAI’s horizon.

The decision to introduce ads also seems to be a response to the growing competition in the field of artificial intelligence and technology services, where other players are already advancing in monetization through advertising. As the market becomes increasingly competitive, OpenAI seeks to diversify its revenue and ensure its long-term sustainability.

This move to incorporate advertising could change the user experience in ChatGPT, a service that has been valued for its ability to interact and respond without commercial interruptions. However, the company hopes that the ads will be relevant and ultimately enhance the overall user experience. With this initiative, OpenAI aligns itself with the monetization strategies that other competitors have been implementing on their platforms, which could be an indication of broader changes in the way artificial intelligence services are funded in the future.