Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»PromptSpy Android Malware Abuses Gemini AI at Runtime for Persistence
    Cybersecurity

    PromptSpy Android Malware Abuses Gemini AI at Runtime for Persistence

    adminBy adminFebruary 21, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Android malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Researchers at ESET have analyzed what they describe as the first Android malware to leverage generative AI during its execution.

    Named PromptSpy, the malware deploys a VNC module on compromised systems, enabling its operators to view the victim’s screen and take full control of the Android device. 

    In addition, PromptSpy can collect device information, capture the lockscreen PIN or password, record the screen to obtain the device’s unlock pattern, and take screenshots.

    For persistence, the Android malware uses a novel approach at runtime that involves sending a prompt to Google’s Gemini gen-AI chatbot along with an XML file containing data about the various UI elements displayed on the screen, including their type, text, and position. 

    Gemini uses this information to tell PromptSpy — via JSON instructions — where to tap or swipe on the screen in order to add the malware to the list of recent apps. The malware can interact with the device and perform the gestures recommended by the AI chatbot by abusing Android’s Accessibility Services. 

    “The malware saves both its previous prompts and Gemini’s responses, allowing Gemini to understand context and to coordinate multistep interactions,” ESET researchers explained. 

    Advertisement. Scroll to continue reading.

    By locking itself in the recent apps list, the malware ensures persistence across device reboots.

    PromptSpy also abuses Accessibility Services to prevent removal. ESET researchers explained, “When the user attempts to uninstall the payload or disable Accessibility Services, the malware overlays transparent rectangles on specific screen areas – particularly over buttons containing substrings like stop, end, clear, and Uninstall. These overlays are invisible to the user but intercept interactions, making removal difficult.”

    “Because PromptSpy blocks uninstallation by overlaying invisible elements on the screen, the only way for a victim to remove it is to reboot the device into Safe Mode, where third‑party apps are disabled and can be uninstalled normally,” the researchers added.

    ESET noted that it has not seen infections in the wild and PromptSpy may be a proof of concept, similar to the PromptLock ransomware detailed by the company last year. 

    However, the security firm has seen a domain that appears to be designed to deliver the malware to users in Argentina.

    Evidence indicates that PromptSpy has been created by Chinese developers. ESET made this attribution with medium confidence and the company has not linked the Android malware to any threat actor. 

    Related: New Keenadu Android Malware Found on Thousands of Devices

    Related: Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security

    Related: New ‘ZeroDayRAT’ Spyware Kit Enables Total Compromise of iOS, Android Devices

    abuses Android Gemini Malware Persistence PromptSpy Runtime
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleThis 27-Inch LG Ultrafine 4K Monitor Just Dropped to Under $200
    Next Article Here are my favorite free watch faces for the Pixel Watch 4
    admin
    • Website

    Related Posts

    NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions

    April 17, 2026

    GitLab 18.11 brings agentic AI to security fixes, CI pipelines, and delivery analytics

    April 17, 2026

    Some Windows servers enter reboot loops after April patches

    April 17, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    These 5 free Microsoft Store apps deserve a place on every Windows PC

    April 17, 2026

    NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions

    April 17, 2026

    AI Agents Are Here And Your Website Isn’t Ready, Says No Hacks Podcast Host

    April 17, 2026

    Wavelet: headphone equalizer 26.04 APK Download by pittvandewitt

    April 17, 2026
    Categories
    • Blogging (63)
    • Cybersecurity (1,362)
    • Privacy & Online Earning (170)
    • SEO & Digital Marketing (836)
    • Tech Tools & Mobile / Apps (1,628)
    • WiFi / Internet & Networking (227)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    These 5 free Microsoft Store apps deserve a place on every Windows PC

    April 17, 2026

    NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions

    April 17, 2026

    AI Agents Are Here And Your Website Isn’t Ready, Says No Hacks Podcast Host

    April 17, 2026
    Most Popular
    • These 5 free Microsoft Store apps deserve a place on every Windows PC
    • NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions
    • AI Agents Are Here And Your Website Isn’t Ready, Says No Hacks Podcast Host
    • Wavelet: headphone equalizer 26.04 APK Download by pittvandewitt
    • GitLab 18.11 brings agentic AI to security fixes, CI pipelines, and delivery analytics
    • OnePlus’ Europe exit isn’t official yet, but the signs aren’t great
    • Some Windows servers enter reboot loops after April patches
    • Why your website is now the source of truth in local AI search
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.