In a notable advancement in mobile cybersecurity threats, researchers from ESET have identified PromptSpy, the first Android malware utilizing generative AI. This malware has been designed to enhance its operational framework by contextually manipulating the user interface, making it harder for users to detect and eliminate it.
Primarily targeting users in Argentina, PromptSpy employs sophisticated financial fraud techniques to exploit victims. It leverages Google’s Gemini AI to analyze screen layouts and generate instructions that help it remain active in the recent apps list, complicating attempts to close the app. Although it has not been found on Google Play, the malware is distributed via phishing sites disguised as legitimate banking services, particularly mimicking Chase Bank.
ESET has alerted Google about this new threat, and Google has confirmed that users with Play Services are protected by Play Protect, which blocks known variants of the malware. This discovery follows the emergence of PromptLock in August 2025, the first AI-driven ransomware, illustrating the quickening pace of generative AI's incorporation into cybercrime strategies.