{"id":586,"date":"2026-09-14T07:00:31","date_gmt":"2026-09-13T21:00:31","guid":{"rendered":"https:\/\/qld.cybersafebusiness.au\/index.php\/2026\/09\/14\/android-malware-promptspy-uses-generative-ai-to-stay-hidden-on-devices\/"},"modified":"2026-09-14T07:00:31","modified_gmt":"2026-09-13T21:00:31","slug":"android-malware-promptspy-uses-generative-ai-to-stay-hidden-on-devices","status":"publish","type":"post","link":"https:\/\/qld.cybersafebusiness.au\/index.php\/2026\/09\/14\/android-malware-promptspy-uses-generative-ai-to-stay-hidden-on-devices\/","title":{"rendered":"Android Malware \u201cPromptSpy\u201d Uses Generative AI to Stay Hidden on Devices"},"content":{"rendered":"<p>We recently reviewed new research from <b>ESET<\/b>, which has identified an Android malware family dubbed <i>PromptSpy<\/i>. According to ESET researcher <b>Luk\u00e1\u0161 \u0160tefanko<\/b>, this appears to be the first observed Android malware sample using generative AI to maintain persistence on infected devices.<\/p>\n<p>The discovery is notable not because AI is controlling the entire attack, but because of how it is being used: to adapt to user interfaces dynamically and make the malware harder to remove.<\/p>\n<p><\/p>\n<h2>What Makes PromptSpy Different?<\/h2>\n<p>PromptSpy uses <b>Google\u2019s Gemini generative AI model<\/b> to interpret what appears on a device\u2019s screen and return instructions for user interface gestures. It then uses those instructions to keep the malicious app locked in the \u201crecent apps\u201d view.<\/p>\n<p>On many Android devices, users can pin or lock apps in the recent apps screen \u2014 often indicated by a padlock icon. PromptSpy leverages AI to identify those interface elements and determine the steps required to keep itself locked in that position.<\/p>\n<p>This makes it harder for users to remove the app simply by swiping it away or relying on standard Android behaviour.<\/p>\n<p>As \u0160tefanko explained:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>\n\u201cSince Android malware often relies on UI-based navigation, leveraging generative AI enables threat actors to adapt to more or less any device, layout, or operating system version, which can greatly increase the pool of potential victims.\u201d\n<\/p>\n<p><cite><\/cite><\/p><\/blockquote>\n<p>The generative AI component is predefined in the malware\u2019s code and cannot be modified without updating the malware itself. While limited to the persistence function, this approach demonstrates how AI can make malware more flexible across different Android versions and device layouts.<\/p>\n<p><\/p>\n<h2>Remote Access Capabilities<\/h2>\n<p>Beyond AI-assisted persistence, PromptSpy includes more traditional remote-access features.<\/p>\n<p>The malware contains a built-in <b>Virtual Network Computing (VNC) module<\/b>, giving attackers remote visibility of the device screen and allowing them to perform actions directly on the handset.<\/p>\n<p>According to ESET, PromptSpy can:<\/p>\n<ul>\n<li>\nCapture lockscreen data\n<\/li>\n<li>\nCollect device information\n<\/li>\n<li>\nTake screenshots\n<\/li>\n<li>\nRecord screen activity as video\n<\/li>\n<li>\nCommunicate with command-and-control servers using AES encryption\n<\/li>\n<\/ul>\n<p>These capabilities are often associated with account takeover activity, particularly targeting mobile banking users.<\/p>\n<p><\/p>\n<h2>Blocking Uninstallation<\/h2>\n<p>PromptSpy abuses Android Accessibility Services and screen overlays to resist removal.<\/p>\n<p>It places invisible overlays over parts of the screen, interfering with user taps during the uninstall process. This makes it appear as if the device is malfunctioning when users attempt to remove the app.<\/p>\n<p>ESET recommends rebooting the device into <b>Safe Mode<\/b>, which disables third-party apps and prevents the overlays from running. From Safe Mode, users can navigate to Settings \u2192 Apps, select the malicious app (named <i>MorganArg<\/i> in this case), and uninstall it.<\/p>\n<p>Steps may vary slightly depending on the device manufacturer.<\/p>\n<p><\/p>\n<h2>Distribution and Targeting<\/h2>\n<p>PromptSpy has been distributed through a dedicated website and has not appeared on Google Play. ESET shared its findings with Google through the App Defence Alliance.<\/p>\n<p>Google Play Protect blocks known versions of the malware on devices with Google Play Services enabled.<\/p>\n<p>ESET\u2019s analysis suggests the campaign is financially motivated and primarily targeting users in Argentina. The malicious app impersonates a banking brand and uses the name <i>MorganArg<\/i>, with an icon resembling Morgan Chase branding.<\/p>\n<p>The researchers note that PromptSpy has not yet appeared in broader telemetry, which may indicate a limited campaign or a proof-of-concept operation.<\/p>\n<p><\/p>\n<h2>Why This Matters<\/h2>\n<p>The AI component in PromptSpy is currently limited to improving persistence. However, it signals a shift in how malware authors may use generative AI in the future.<\/p>\n<p>Rather than replacing traditional malware techniques, AI may enhance them by:<\/p>\n<ul>\n<li>\nAdapting automatically to different device layouts\n<\/li>\n<li>\nAutomating interaction sequences\n<\/li>\n<li>\nReducing the need for device-specific scripting\n<\/li>\n<\/ul>\n<p>\u0160tefanko noted:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>\n\u201cEven though PromptSpy uses Gemini in just one of its features, it still demonstrates how implementing these tools can make malware more dynamic, giving threat actors ways to automate actions that would normally be more difficult with traditional scripting.\u201d\n<\/p>\n<p><cite><\/cite><\/p><\/blockquote>\n<h2>CSB Perspective<\/h2>\n<p>At CSB, we see PromptSpy as an early example of AI being used to make attacks more adaptable rather than more complex.<\/p>\n<p>While the current use case is limited, it demonstrates how AI can help malware overcome small technical barriers that once required manual refinement by attackers. Over time, this could lower the barrier to entry for less sophisticated threat actors.<\/p>\n<p>Organisations should consider this a reminder that mobile devices are no longer secondary endpoints \u2014 they are primary gateways to banking apps, corporate email, authentication systems, and cloud services.<\/p>\n<p>Practical steps for users and organisations include:<\/p>\n<ul>\n<li>\nOnly installing apps from official app stores\n<\/li>\n<li>\nReviewing Accessibility permissions carefully\n<\/li>\n<li>\nKeeping devices updated\n<\/li>\n<li>\nEnsuring Google Play Protect or equivalent protections are enabled\n<\/li>\n<li>\nUsing strong, phishing-resistant authentication methods where possible\n<\/li>\n<\/ul>\n<p>&nbsp;For businesses, mobile device management (MDM) and conditional access controls can significantly reduce the risk of compromised mobile devices accessing sensitive systems.<\/p>\n<p>AI-powered malware is not yet widespread in the mobile space. However, PromptSpy shows how attackers are experimenting with generative AI to increase automation and resilience.<\/p>\n<p>The key takeaway is not alarm, but awareness. AI is becoming part of the attacker toolkit \u2014 and defenders must continue evolving visibility, identity protection, and endpoint controls accordingly.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We recently reviewed new research from ESET, which has identified an Android malware family dubbed PromptSpy. According to ESET researcher Luk\u00e1\u0161 \u0160tefanko, this appears to be the first observed Android [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":585,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[],"tags":[],"class_list":["post-586","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/posts\/586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/comments?post=586"}],"version-history":[{"count":0,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/posts\/586\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/media\/585"}],"wp:attachment":[{"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/media?parent=586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/categories?post=586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/tags?post=586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}