First Android Malware Abuses Google’s Gemini AI

AI malware abuses Gemini, hijacks Android devices, targets Argentina.

  • Security researchers have discovered PromptSpy, an advanced Android malware that abuses Google’s Gemini AI for persistence and device control.
  • The malware is designed to capture lockscreen data, block uninstallation, gather information, take screenshots, and enable remote VNC access, primarily targeting users in Argentina.
  • PromptSpy signifies a new evolution in mobile threats, using generative AI to adapt to any device UI, making conventional removal techniques ineffective.

Cybersecurity researchers at ESET have announced the discovery of the first known Android malware, codenamed PromptSpy, that actively exploits Google’s Gemini AI chatbot to maintain control over infected devices according to a recent report. The malware, distributed outside of Google Play via a dedicated website, uses Gemini to analyze the device’s screen and receive step-by-step instructions for locking the app in the recent apps list, preventing it from being killed.

- Advertisement -

Consequently, the primary function of PromptSpy is to deploy a VNC module that grants attackers remote access to the victim’s device. It also uses accessibility services to overlay invisible elements on the screen, blocking standard uninstallation attempts and capturing sensitive lockscreen data.

The campaign is financially motivated and, based on language clues, primarily targets users in Argentina. Meanwhile, evidence in the code, including debug strings in simplified Chinese, suggests PromptSpy was developed in a Chinese-speaking environment, as noted by researcher Lukáš Štefanko.

This use of AI makes the malware highly adaptive to different device layouts and Android versions. The only effective removal method is for victims to reboot the device into Safe Mode to uninstall third-party apps.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -

Latest News

Kraken’s Tokenized Stock Platform Hits $25B Volume

Kraken's tokenized equities platform, xStocks, exceeded $25 billion in total transaction volume within eight...

Coinbase Base Ditchs Optimism Stack, OP Token Plunges

Coinbase's Base Blockchain is severing its core partnership with Optimism by no longer using...

Sharplink’s $1.68B ETH Treasury Gains Major Institutional Backing

Sharplink, Inc. now holds approximately 867,798 ETH, valued at $1.68 billion, and has seen...

Beeple Depicts ETHDenver 2026 as Post-Apocalyptic Wasteland

NFT artist Beeple's new painting depicts ETHDenver 2026 as a desolate, post-apocalyptic wasteland with...

White House Hosts New Talks on Stalled Crypto Bill CLARITY Act

White House officials met with crypto and banking reps to resolve differences on the...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!