PromptSpy: First Android Malware Utilizing Generative AI Discovered

PromptSpy: First Android Malware Utilizing Generative AI Discovered

First seen 19 Feb 2026, 15:18 UTC Feeds2.FeedburnerWelivesecurityComputerweeklyCybersecuritynewsTheregister+33 86% similarity 40.3

Article Content

Browse articles
ThreatCluster

ESET researchers have identified PromptSpy, the first Android malware to incorporate generative AI, specifically Google’s Gemini, in its execution flow. This malware utilizes AI to manipulate the user interface and maintain persistence on infected devices, capturing sensitive data and preventing uninstallation. PromptSpy represents a significant evolution in mobile threats, following the earlier discovery of AI-powered ransomware, PromptLock.

ThreatCluster AI

Timeline

2025-08-01
ESET identified PromptLock, the first AI-powered ransomware
2026-02-19
PromptSpy malware discovered by ESET researchers

Community

Browse all →