PromptSpy marks a new era in Android security as ESET harnesses Gemini AI for malware innovation

PromptSpy marks a new era in Android security as ESET harnesses Gemini AI for malware innovation

The emergence of PromptSpy marks a drastic shift in mobile security, as the first generative AI malware targets users in Argentina, complicating detection through dynamic UI manipulation.

NeboAI I summarize the news with data, figures and context
IN 30 SECONDS

IN 1 SENTENCE

SENTIMENT
Neutral

𒀭
NeboAI is working, please wait...
Preparing detailed analysis
Quick summary completed
Extracting data, figures and quotes...
Identifying key players and context
DETAILED ANALYSIS
SHARE

NeboAI produces automated editions of journalistic texts in the form of summaries and analyses. Its experimental results are based on artificial intelligence. As an AI edition, texts may occasionally contain errors, omissions, incorrect data relationships and other unforeseen inaccuracies. We recommend verifying the content.

In a notable advancement in mobile cybersecurity threats, researchers from ESET have identified PromptSpy, the first Android malware utilizing generative AI. This malware has been designed to enhance its operational framework by contextually manipulating the user interface, making it harder for users to detect and eliminate it.

Primarily targeting users in Argentina, PromptSpy employs sophisticated financial fraud techniques to exploit victims. It leverages Google’s Gemini AI to analyze screen layouts and generate instructions that help it remain active in the recent apps list, complicating attempts to close the app. Although it has not been found on Google Play, the malware is distributed via phishing sites disguised as legitimate banking services, particularly mimicking Chase Bank.

ESET has alerted Google about this new threat, and Google has confirmed that users with Play Services are protected by Play Protect, which blocks known variants of the malware. This discovery follows the emergence of PromptLock in August 2025, the first AI-driven ransomware, illustrating the quickening pace of generative AI's incorporation into cybercrime strategies.

Want to read the full article? Access the original article with all the details.
Read Original Article
TL;DR

This article is an original summary for informational purposes. Image credits and full coverage at the original source. · View Content Policy

Editorial
Editorial Staff

Our editorial team works around the clock to bring you the latest tech news, trends, and insights from the industry. We cover everything from artificial intelligence breakthroughs to startup funding rounds, gadget launches, and cybersecurity threats. Our mission is to keep you informed with accurate, timely, and relevant technology coverage.

Press Enter to search or ESC to close