PromptSpy: First Android AI Malware Leverages Google’s Gemini for Decision-Making
PromptSpy represents a newly identified Android malware family that exploits Google's Gemini generative AI model. Its primary function is to make real-time decisions to manipulate user interfaces and maintain persistence on compromised devices.
PromptSpy represents a newly identified Android malware family that exploits Google's Gemini generative AI model. Its primary function is to make real-time decisions to manipulate user interfaces and maintain persistence on compromised devices.
PromptSpy's AI-enhanced operations focus on persistence rather than initial infection or data theft. It uses Gemini by sending natural-language prompts and XML snapshots of the current screen, including text, type, and bounds of each element. Gemini then provides JSON instructions on the gestures to perform, enabling PromptSpy to maintain its presence in the Recent Apps list, even when users attempt to close it.
This malware is the first known Android threat to utilize generative AI for stealthy persistence and complete remote control of affected devices. It communicates with Gemini to execute these tasks efficiently across various devices, OEM skins, and OS versions.
Beyond its AI-driven persistence, PromptSpy operates as a remote-access tool facilitated by a built-in VNC component. Upon obtaining Accessibility permissions, operators can view device screens in real time, simulate gestures, and perform actions as if physically handling the phone. The malware can capture lockscreen credentials, collect device information, take screenshots, and record screen activities.
Communication with a hardcoded command-and-control (C2) server over the VNC protocol is encrypted using AES, and the C2 can deliver Gemini API key campaigns and tasking instructions to the malware.
ESET's research indicates that PromptSpy is part of a financially motivated campaign targeting users in Argentina. Initial samples were uploaded to VirusTotal from Hong Kong in January 2026, with more sophisticated builds appearing from Argentina in February 2026. The distribution used domains mimicking JPMorgan Chase branding, suggesting a banking fraud theme.
PromptSpy is not available on Google Play, but Google Play Protect now detects known variants, providing automatic protection for devices with Play Services enabled.
PromptSpy represents a newly identified Android malware family that exploits Google's Gemini generative AI model.
SHA-1 Filename Detection Description
6BBC9AB132BA066F63676E05DA13D108598BC29B net.ustexas.myavlive.apk Android/Spy.VNCSpy.A Android VNCSpy malware.
375D7423E63C8F5F2CC814E8CFE697BA25168AFA nlll4.un7o6.q38l5.apk Android/Spy.VNCSpy.A Android VNCSpy malware.
3978AC5CD14E357320E127D6C87F10CB70A1DCC2 ppyzz.dpk0p.ln441.apk Android/Spy.VNCSpy.A Android VNCSpy malware.
E60D12017D2DA579DF87368F5596A0244621AE86 mgappc-1.apk Android/Spy.PromptSpy.A Android PromptSpy dropper.
9B1723284E311794987997CB7E8814EB6014713F mgappm-1.apk Android/Spy.PromptSpy.A Android PromptSpy dropper.
076801BD9C6EB78FC0331A4C7A22C73199CC3824 mgappn-0.apk Android/Spy.PromptSpy.A Android PromptSpy dropper.
8364730E9BB2CF3A4B016DE1B34F38341C0EE2FA mgappn-1.apk Android/Spy.PromptSpy.A Android PromptSpy dropper.
F8F4C5BC498BCCE907DC975DD88BE8D594629909 app-release.apk Android/Spy.PromptSpy.A Android PromptSpy.
C14E9B062ED28115EDE096788F62B47A6ED841AC mgapp.apk Android/Phishing.Agent.M Android phishing malware.
Based on reporting by GBHackers.
