AI-Powered Malware ‘PromptSpy’ Targets Android Users with Novel Attack Method
Cybersecurity researchers have uncovered a fresh Android malware strain dubbed “PromptSpy” that marks a significant escalation in mobile threats. This malware is the first known instance of malicious software leveraging generative artificial intelligence – specifically, Google’s Gemini – during its operation. PromptSpy doesn’t just install itself. it actively uses AI to maintain its persistence on a compromised device, adapting to different Android versions and user interfaces. The discovery, initially reported by European cybersecurity firm ESET, signals a potentially disruptive shift in the tactics employed by cybercriminals, moving beyond traditional methods to exploit the capabilities of advanced AI models. ESET’s research details how PromptSpy utilizes Gemini to interpret on-screen elements and execute gestures, effectively hiding within the recent apps list.
The malware is disguised as a fake banking application named “MorganArg,” according to ESET’s analysis. Once installed, it requests a series of permissions from the user. Granting these permissions grants the attackers nearly complete control over the device. This includes the ability to monitor screen activity, intercept messages, and potentially execute financial transactions. The sophistication of PromptSpy lies not just in its access capabilities, but in its ability to adapt and remain undetected, a feat previously unattainable without the integration of generative AI. This new approach to malware persistence represents a significant challenge for mobile security, as traditional detection methods may prove ineffective against such dynamic and adaptive threats.
Full Device Control and Data Exfiltration
PromptSpy grants attackers extensive privileges on the infected device. ESET researchers found the malware can capture data from the lock screen, block attempts to uninstall it, gather detailed device information, take screenshots, and even record screen activity as video. This level of access allows attackers to monitor user behavior, steal sensitive information like passwords and financial details, and potentially conduct fraudulent activities. The ability to disable key functions through invisible layers further complicates removal, making it difficult for users to simply terminate the malicious application. SecurityWeek reported that the malware essentially provides attackers with remote control over the victim’s device, akin to physically holding it.
Gemini AI Enables Adaptive Persistence
What sets PromptSpy apart is its innovative use of generative AI. Instead of relying on pre-programmed instructions, the malware sends screenshots of the current screen to Google’s Gemini AI model. Gemini then analyzes the screen and provides PromptSpy with step-by-step instructions on how to remain pinned in the recent apps list, preventing it from being easily closed or killed by the system. This dynamic approach allows PromptSpy to adapt to different Android versions, device layouts, and operating system configurations, significantly expanding its potential victim pool. WeLiveSecurity explained that the AI model and prompt are predefined within the malware’s code and cannot be altered by the user, highlighting the deliberate and sophisticated nature of the attack.
The developers of PromptSpy appear to have connections to a Chinese-speaking environment, based on language localization clues and distribution vectors observed during analysis. The malicious application has not been found in official app stores, suggesting it is distributed through alternative channels. Experts emphasize the importance of downloading applications only from trusted sources, such as the Google Play Store, and exercising caution when granting broad permissions, particularly those related to accessibility services. Misuse of these permissions can lead to remote control of the device, as demonstrated by PromptSpy’s capabilities.
Protecting Yourself from AI-Powered Malware
While PromptSpy has not yet been widely observed in ESET telemetry, potentially indicating it is still in a proof-of-concept phase, the threat it represents is very real. Regularly updating your device’s operating system is a crucial step in mitigating the risk, as updates often include security patches that address vulnerabilities exploited by malware. If you suspect your device has been infected, booting it into safe mode can often allow you to uninstall the problematic application. Google Play Protect, which is enabled by default on most Android devices, can likewise detect and remove known malware variants. Yet, given PromptSpy’s adaptive nature, relying solely on traditional antivirus solutions may not be sufficient.
ESET researchers also noted this is the second AI-powered malware they have discovered, following PromptLock in August 2025, which was the first known case of AI-driven ransomware. This suggests a growing trend of cybercriminals exploring the potential of AI to enhance their malicious activities. The use of AI in malware development is likely to become more prevalent, requiring a continuous evolution of security measures to stay ahead of these emerging threats. The ability of PromptSpy to leverage Gemini for UI manipulation demonstrates a new level of sophistication, and it is crucial for both users and security professionals to understand the implications of this technology.
Key Takeaways
- Novel AI Integration: PromptSpy is the first Android malware to utilize generative AI (Google’s Gemini) for dynamic operation and persistence.
- Adaptive Persistence: The malware uses AI to analyze the screen and execute gestures to remain hidden in the recent apps list, adapting to different devices and Android versions.
- Full Device Control: Once installed, PromptSpy grants attackers extensive access to device functions, including screen monitoring, data exfiltration, and remote control.
- Disguised Application: The malware is distributed as a fake banking application (“MorganArg”) to deceive users into installing it.
- Proactive Protection: Users should download apps only from trusted sources, keep their devices updated, and be cautious about granting broad permissions.
The discovery of PromptSpy underscores the evolving landscape of mobile security and the increasing sophistication of cyber threats. As AI technology continues to advance, it is likely that we will see more malware strains incorporating similar techniques. Ongoing research and collaboration between cybersecurity firms and technology providers will be essential to develop effective defenses against these emerging threats. The next update from ESET regarding PromptSpy is expected in early March 2026, as they continue to analyze its behavior and potential impact. Stay informed and share this information with your network to help protect against this evolving threat.
Keep reading