Promptsteal Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
16
occurrences
First Seen
November 5, 2025
Last Seen
February 19, 2026

Related Threat Clusters

  • Google Identifies AI-Driven Malware Families with Self-Modifying Capabilities

    Google's Threat Intelligence Group has discovered at least five new malware families that utilize artificial intelligence for self-modification during execution. This technique, referred to as 'just-in-time'…

    2 articles · Updated November 5, 2025
  • Google GTIG Reports Shift in AI Misuse by Cyber Adversaries

    The Google Threat Intelligence Group (GTIG) has identified a new operational phase of AI abuse, where adversaries are deploying AI-enabled malware in live operations. This shift indicates that threat actors are moving…

    3 articles · Updated November 5, 2025
  • PromptSpy: First Android Malware Utilizing Generative AI Discovered

    ESET researchers have identified PromptSpy, the first Android malware to incorporate generative AI, specifically Google’s Gemini, in its execution flow. This malware utilizes AI to manipulate the user interface and…

    39 articles · Updated February 19, 2026
  • Gemini AI Misused for Developing Self-Modifying Malware by Cybercriminals

    Nation-state actors and cybercrime groups are utilizing Gemini AI to create a 'Thinking Robot' malware module capable of rewriting its own code to evade detection. This development also includes an AI agent designed to…

    2 articles · Updated November 5, 2025
  • Debate on AI SOC Agents and Security Outcomes

    The discussion around AI Security Operations Centers (SOCs) is evolving, with Gartner's report highlighting the mainstream recognition of AI's potential in enhancing SOC functions. However, critiques emphasize that…

    52 articles · Updated November 16, 2025
  • Gemini AI Misused for Advanced Malware Development by Cybercriminals

    Nation-state actors and cybercrime organizations are leveraging Gemini AI to create a 'Thinking Robot' malware module capable of self-modification to evade detection. This malware can also develop AI agents for tracking…

    2 articles · Updated November 5, 2025

Recent Intelligence Reports

  • This Android Malware Connects to Google Gemini for Tips on Hacking Targets — Uk.Pcmag · February 19, 2026
  • PromptSpy Android malware may exploit Gemini AI — Computerweekly · February 19, 2026
  • Anthropic warns state — Cybersecuritydive · November 14, 2025
  • AI Malware Detected in the Wild as Threats Evolve — Thecyberexpress · November 7, 2025
  • Google warns of AI-powered malware targeting crypto users — Invezz · November 7, 2025
  • Google Threat Report Links AI-powered Malware to DPRK Crypto Theft — Decrypt.Co · November 7, 2025
  • Google finds first evidence of AI-enabled malware in the wild — Digit.Fyi · November 6, 2025
  • AI-Powered Malware Evolves: Google Uncovers Live Use of Generative Models in Active Intrusions — Circleid · November 6, 2025

CVSS v3.1 Breakdown