ESET researchers have uncovered PromptSpy, the first known Android malware to dynamically abuse Google’s Gemini generative AI to manipulate user interfaces during attacks.
This threat marks a shift in mobile malware tactics, using AI to adapt persistence mechanisms across diverse Android devices and layouts.
PromptSpy uses Gemini solely to keep the malicious app locked in the recent apps list, preventing easy swipes or system kills.
The malware captures an XML dump of the current screen, detailing every UI element’s text, type, and position, then sends it along with a hardcoded natural-language prompt to Gemini, which acts as an “Android automation assistant.”
Gemini responds with JSON instructions for precise taps, long clicks, or swipes, creating a feedback loop until success is confirmed, as evidenced by visual cues such as a padlock icon.
This approach overcomes limitations of traditional hardcoded coordinates or selectors, which fail across OS versions, manufacturers, or skins.
By automating context-aware gestures via AI, PromptSpy expands its victim pool without custom scripts per device.

ESET notes this as the second AI-malware discovery after PromptLock ransomware in August 2025, highlighting generative AI’s growing role in dynamic threat execution.
Core Malicious Features
Beyond AI persistence, PromptSpy’s primary function deploys a VNC module for remote operator access, enabling full-screen viewing and control, such as taps, swipes, and inputs.
It abuses Accessibility Services to read screen content, block uninstalls with invisible overlays on buttons like “Uninstall” or “Stop,” capture lockscreen PINs/patterns via video, take screenshots, record activity, and report device details or foreground apps.
Communication occurs over VNC protocol to a hardcoded C2 server at 54.67.2[.]84, with AES-encrypted messages. The malware requests a Gemini API key from C2, lists installed apps, and targets screen recordings for operator-specified apps.

Anti-removal overlays render standard uninstalls ineffective; victims must reboot into Safe Mode typically via long-pressing Power off from the power menu to turn off third-party apps and remove them.
Distribution and Attribution
Samples surfaced on VirusTotal: VNCSpy precursors from Hong Kong in January 2026, and advanced PromptSpy droppers from Argentina in February.
Distributed via mgardownload[.]com (offline), droppers posed as “MorganArg” apps mimicking Chase Bank, prompting manual payload installs from embedded app-release.apk. A companion phishing trojan shared signing certificates and fake Spanish banking sites on m-mgarg[.]com.
Localization clues point to financial motives targeting Argentina, yet debug strings in simplified Chinese and handlers for Chinese Accessibility events suggest development in a Chinese-speaking environment.

No telemetry hits indicate possible proof-of-concept status, though distribution domains imply wild deployment. ESET shared findings with Google via App Defense Alliance; Play Protect blocks known variants by default.
| IP/Domain | Details | First Seen | Hosting |
|---|---|---|---|
| 52.222.205[.]45 | m-mgarg[.]com (phishing) | 2026-01-12 | Amazon |
| 54.67.2[.]84 | C2 server | N/A | Amazon |
| 104.21.91[.]170 | mgardownload[.]com (distribution) | 2026-01-13 | Cloudflare |
According to welivesecurity, promptSpy signals evolving Android threats, where AI enables real-time adaptation, urging vigilance against sideloading and Accessibility prompts. Full IoCs at ESET’s GitHub.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.