Malware & Threats

PromptSpy Android Malware Abuses Gemini AI at Runtime for Persistence

The malware leverages Gemini to analyze on-screen elements and ensure that it remains on the device even after a reboot.

Android malware

Researchers at ESET have analyzed what they describe as the first Android malware to leverage generative AI during its execution.

Named PromptSpy, the malware deploys a VNC module on compromised systems, enabling its operators to view the victim’s screen and take full control of the Android device. 

In addition, PromptSpy can collect device information, capture the lockscreen PIN or password, record the screen to obtain the device’s unlock pattern, and take screenshots.

For persistence, the Android malware uses a novel approach at runtime that involves sending a prompt to Google’s Gemini gen-AI chatbot along with an XML file containing data about the various UI elements displayed on the screen, including their type, text, and position. 

Gemini uses this information to tell PromptSpy — via JSON instructions — where to tap or swipe on the screen in order to add the malware to the list of recent apps. The malware can interact with the device and perform the gestures recommended by the AI chatbot by abusing Android’s Accessibility Services. 

“The malware saves both its previous prompts and Gemini’s responses, allowing Gemini to understand context and to coordinate multistep interactions,” ESET researchers explained. 

Advertisement. Scroll to continue reading.

By locking itself in the recent apps list, the malware ensures persistence across device reboots.

PromptSpy also abuses Accessibility Services to prevent removal. ESET researchers explained, “When the user attempts to uninstall the payload or disable Accessibility Services, the malware overlays transparent rectangles on specific screen areas – particularly over buttons containing substrings like stop, end, clear, and Uninstall. These overlays are invisible to the user but intercept interactions, making removal difficult.”

“Because PromptSpy blocks uninstallation by overlaying invisible elements on the screen, the only way for a victim to remove it is to reboot the device into Safe Mode, where third‑party apps are disabled and can be uninstalled normally,” the researchers added.

ESET noted that it has not seen infections in the wild and PromptSpy may be a proof of concept, similar to the PromptLock ransomware detailed by the company last year. 

However, the security firm has seen a domain that appears to be designed to deliver the malware to users in Argentina.

Evidence indicates that PromptSpy has been created by Chinese developers. ESET made this attribution with medium confidence and the company has not linked the Android malware to any threat actor. 

Related: New Keenadu Android Malware Found on Thousands of Devices

Related: Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security

Related: New ‘ZeroDayRAT’ Spyware Kit Enables Total Compromise of iOS, Android Devices

Related Content

Malware & Threats

The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.

Artificial Intelligence

From defending networks to enabling attacks, artificial intelligence is changing every aspect of cybersecurity. Here's what dozens of experts say security leaders need to...

Artificial Intelligence

A group of cybersecurity executives and experts is asking the Trump administration to lift its directive preventing the use of Anthropic’s latest artificial intelligence...

Artificial Intelligence

Anthropic takes Fable 5 and Mythos 5 offline to comply with a directive from the Trump administration to prevent use by foreign nationals.

Artificial Intelligence

Industry professionals comment on various aspects of Fable 5, including dual-use capabilities, safeguards, and tiered access.

Artificial Intelligence

An AI hacker claims to have achieved a prompt-based jailbreak shortly after Fable 5’s launch, but Anthropic says it’s not a real jailbreak.

Incident Response

As alert volumes outpace human capacity, organizations are turning to AI, automation, and deeper context to separate real threats from the noise.

Cybercrime

Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version