Android Malware Taps Gemini to Navigate Infected Devices
PromptSpy uses Google’s Gemini AI to improve persistence and enable remote control on Android devices, targeting Argentina with phishing domains impersonating JPMorgan Chase, ESET found.
- ESET discovered PromptSpy, an Android malware that uses Google's Gemini AI to interpret device UI and deploy a VNC module for remote control, enabling persistence.
- By design, the malware leverages generative AI to adapt to different devices and UI layouts, expanding victims; ESET traced VNCSpy on VirusTotal from January 13th, 2026, with targeting focused on Argentina.
- Technically, PromptSpy operates by sending a natural-language prompt and XML screen dump to Gemini, which returns JSON to perform taps via Accessibility Service and a VNC module, while overlaying transparent rectangles to block uninstall, forcing Safe Mode removal.
- ESET cautioned that despite domains m-mgargcom and mgardownloadcom impersonating JPMorgan Chase, it has not seen PromptSpy in ESET telemetry, saying, `We haven't seen any signs of the PromptSpy dropper or its payload in our telemetry so far, which could mean they're only proofs of concept.`
- Looking ahead, the discovery positions PromptSpy as the first Android malware using generative AI, while Google Threat Intelligence and NYU student researchers highlight the generative AI threat trend.
19 Articles
19 Articles
Researchers from the European IT security company ESET have discovered a new Android malware that Google uses to protect itself from closing and remain permanently active on the device. Cybercriminals have thus crossed a technological threshold, the company warned in a communication. The malware called PromptSpy disguises itself as a banking app "MorganArgi (a fake of the Chase/JPMorgan app) and is spread over fake websites. So far, the campaign…
Android malware is now using Gemini AI to adapt in real time (Updated: Google statement)
Credit: Joe Maring / Android Authority TL;DR Researchers have identified the first known Android malware to use generative AI during execution. The malware queries Google’s Gemini model to adapt its behavior across different Android devices. It may be a proof-of-concept version, but it signals a shift toward more dynamic AI-assisted attacks. Update: February 20, 2026 (05:12 PM ET): Following our request for comment and the publication of the or…
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









