PromptSpy: First Android Malware Abusing Generative AI Discovered by ESET
ESET researchers have identified PromptSpy, the first known Android malware to integrate generative AI into its execution flow. Unlike previous threats using traditional machine learning for ad fraud, PromptSpy leverages Google’s Gemini model to achieve persistence on compromised devices. The malware sends screen data to the AI, which provides dynamic, step-by-step instructions to keep the malicious app pinned in the recent apps list, effectively bypassing device-specific UI variations and OS versions. This adaptability allows the threat to survive across diverse Android environments. Beyond its AI-driven persistence mechanism, PromptSpy deploys a VNC module for remote access, utilizes Accessibility Services to block uninstallation via invisible overlays, and captures sensitive data including lockscreen information and video recordings. Although the malware appears to be developed in a Chinese-speaking environment, current distribution vectors suggest it primarily targets users in Argentina. PromptSpy is distributed through dedicated websites rather than the Google Play Store. ESET has shared these findings with Google, and Android devices with Google Play Protect are automatically protected against known versions. This discovery marks a significant evolution in mobile threats, following the earlier detection of AI-driven ransomware, highlighting the increasing sophistication of cybercriminal tactics.
Wire timeline
PromptSpy: First Android Malware Abusing Generative AI Discovered by ESET
ESET researchers have identified PromptSpy, the first known Android malware to integrate generative AI into its execution flow. Unlike previous threats using traditional machine learning for ad fraud, PromptSpy leverages Google’s Gemini model to achieve persistence on compromised devices. The malware sends screen data to the AI, which provides dynamic, step-by-step instructions to keep the malicious app pinned in the recent apps list, effectively bypassing device-specific UI variations and OS versions. This adaptability allows the threat to survive across diverse Android environments. Beyond its AI-driven persistence mechanism, PromptSpy deploys a VNC module for remote access, utilizes Accessibility Services to block uninstallation via invisible overlays, and captures sensitive data including lockscreen information and video recordings. Although the malware appears to be developed in a Chinese-speaking environment, current distribution vectors suggest it primarily targets users in Argentina. PromptSpy is distributed through dedicated websites rather than the Google Play Store. ESET has shared these findings with Google, and Android devices with Google Play Protect are automatically protected against known versions. This discovery marks a significant evolution in mobile threats, following the earlier detection of AI-driven ransomware, highlighting the increasing sophistication of cybercriminal tactics.
WeLiveSecurity