First Android Malware Abuses Google’s Gemini AI

AI malware abuses Gemini, hijacks Android devices, targets Argentina.

  • Security researchers have discovered PromptSpy, an advanced Android malware that abuses Google’s Gemini AI for persistence and device control.
  • The malware is designed to capture lockscreen data, block uninstallation, gather information, take screenshots, and enable remote VNC access, primarily targeting users in Argentina.
  • PromptSpy signifies a new evolution in mobile threats, using generative AI to adapt to any device UI, making conventional removal techniques ineffective.

Cybersecurity researchers at ESET have announced the discovery of the first known Android malware, codenamed PromptSpy, that actively exploits Google’s Gemini AI chatbot to maintain control over infected devices according to a recent report. The malware, distributed outside of Google Play via a dedicated website, uses Gemini to analyze the device’s screen and receive step-by-step instructions for locking the app in the recent apps list, preventing it from being killed.

- Advertisement -

Consequently, the primary function of PromptSpy is to deploy a VNC module that grants attackers remote access to the victim’s device. It also uses accessibility services to overlay invisible elements on the screen, blocking standard uninstallation attempts and capturing sensitive lockscreen data.

The campaign is financially motivated and, based on language clues, primarily targets users in Argentina. Meanwhile, evidence in the code, including debug strings in simplified Chinese, suggests PromptSpy was developed in a Chinese-speaking environment, as noted by researcher Lukáš Štefanko.

This use of AI makes the malware highly adaptive to different device layouts and Android versions. The only effective removal method is for victims to reboot the device into Safe Mode to uninstall third-party apps.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -

Latest News

MEV bot sandwiches user for millions in $50M swap

A crypto trader lost millions swapping $50.4 million USDt for just 327 AAVE tokens...

White House Demands ABC News Retract Iran Drone Report

The White House demanded ABC News retract a story about a potential Iranian drone...

Robinhood Crypto Volumes Leap 74% as Bitcoin Holds Strong

Robinhood's crypto trading volume surged 74% YoY in February 2026 to $25.0 billion, despite...

BlackRock’s Ethereum Staking ETF Debuts With $15.5M Volume

BlackRock's new staked Ethereum ETF, ETHB, launched with $15.5 million in trading volume, described...

$50M AAVE Swap Yields $36K Despite Warning

A trader lost nearly $50 million on Thursday after swapping that amount of USDT...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...