PromptSpy — First Android Malware Using Generative AI (Gemini) for Context-Aware UI Manipulation, VNC Remote Access, Chase Bank Impersonation
PromptSpy — First Android Malware Using Generative AI (TL-2026-0135) is a high-severity malware campaign, first published 2026-02-23. It carries a reported China nexus and is not formally attributed, maps to 19 MITRE ATT&CK techniques (T1398, T1406.002, T1417.001), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-0135
- Threat ID
- TL-2026-0135
- Severity
- HIGH
- Status
- MONITORING
- Category
- MALWARE
- First published
- 2026-02-23
- Last reviewed
- 2026-02-23
- Attribution confidence
- NONE
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in PromptSpy — First Android Malware Using Generative AI
Malware and tooling: PromptSpy
ESET researchers discovered PromptSpy, the first known Android malware to abuse generative AI (Google Gemini) in its execution flow. The malware sends Gemini natural-language prompts with XML dumps of the current screen to dynamically navigate UI and achieve persistence across any device, layout, or OS version. Its primary payload deploys a VNC module for full remote device access with AES-encrypted C2 communication.
How PromptSpy — First Android Malware Using Generative AI works
PromptSpy represents a paradigm shift in mobile malware — the first Android threat to incorporate generative AI (Google Gemini) directly into its execution flow. Discovered by ESET in February 2026, this malware family demonstrates how attackers can leverage large language models to create adaptive, device-agnostic malware that breaks free from the limitations of hardcoded UI automation scripts.
The malware operates as a two-stage dropper architecture. The PromptSpy dropper (distributed via mgardownload[.]com) installs the core payload (app-release.apk) which contains the malicious VNC and AI capabilities. Upon installation, the dropper displays a fake Chase Bank (JPMorgan Chase N.A.) website hosted on m-mgarg[.]com, branded as "MorganArg" — likely targeting Argentine users with a financial services lure.
The AI-powered component works through a continuous feedback loop: PromptSpy uses Accessibility Services to open the Recent Apps screen and collects a detailed XML dump of all visible UI elements including text, content descriptions, class names, package names, and screen bounds. This XML snapshot is sent to Google's Gemini API along with hardcoded natural-language prompts instructing the AI to analyze the UI and return JSON-formatted step-by-step instructions for performing the "lock app in recent apps" gesture. The malware executes these instructions via Accessibility Services, sends the updated screen state back to Gemini, and continues until Gemini confirms the app is successfully locked. This AI-driven approach replaces traditional hardcoded tap coordinates and UI selectors, making the malware resilient to UI changes across different devices, manufacturers, and Android versions.
The primary malicious capability is a built-in VNC module that gives operators full remote access to compromised devices — real-time screen viewing and complete device control including taps, swipes, gestures, and text input. C2 communication uses the VNC protocol over a hardcoded server (54.67.2[.]84) with AES encryption using a hardcoded key. Through this channel, the malware receives Gemini API keys, uploads installed app lists, intercepts lockscreen PINs/passwords, captures pattern unlock screens as video recordings, reports screen state and foreground apps, records screen activity for server-specified apps, and takes screenshots on demand.
Anti-removal capabilities exploit Accessibility Services to overlay transparent rectangles on screen areas containing buttons with substrings like "stop", "end", "clear", and "Uninstall" — invisible to users but intercepting all touch interactions on those elements. The only removal method is rebooting into Safe Mode where third-party apps are disabled.
The predecessor VNCSpy appeared on VirusTotal on January 13, 2026 (uploaded from Hong Kong) with three samples. Four PromptSpy dropper samples appeared on February 10, 2026 from Argentina. A companion phishing app (Android/Phishing.Agent.M) shares the same distribution domain, app name, icon, and developer certificate, likely serving as an initial stage leading victims to install PromptSpy.
Development artifacts include debug strings in simplified Chinese and handling for Chinese Accessibility event types, suggesting development in a Chinese-speaking environment. ESET classifies this with medium confidence. This is ESET's second AI-powered malware discovery after PromptLock ransomware (August 2025), the first known case of AI-driven ransomware.
PromptSpy has not been observed in ESET telemetry yet, possibly indicating proof-of-concept status, but the existence of distribution domains and companion apps suggests active development toward deployment. Android users with Google Play Protect enabled are automatically protected against known versions.
MITRE ATT&CK techniques used in TL-2026-0135
Persistence
T1398 Boot or Logon Initialization Scripts; T1541 Foreground Persistence
Defense Evasion
T1406.002 Obfuscated Files or Information: Software Packing; T1516 Input Injection; T1629.001 Impair Defenses: Prevent Application Removal; T1655 Masquerading
Credential Access
T1417.001 Input Capture: Keylogging; T1417.002 Input Capture: GUI Input Capture
discovery
Discovery
T1426 System Information Discovery
Initial Access
T1476 Deliver Malicious App via Other Means; T1660 Phishing
Collection
T1512 Video Capture; T1513 Screen Capture; T1636 Protected User Data
Command and Control
T1521.001 Encrypted Channel: Symmetric Cryptography; T1663 Remote Access Software
Execution
Exfiltration
Timeline of PromptSpy — First Android Malware Using Generative AI
- ESET discovers PromptLock, the first known AI-powered ransomware — predecessor in ESET's AI malware research series.
- Dr.WEB discovers Android.Phantom using TensorFlow ML models for ad fraud — prior art for ML in Android malware (not GenAI).
- Phishing domain m-mgarg[.]com first seen, hosted on Amazon AWS (52.222.205[.]45). Impersonates Chase Bank for Argentine users.
- Three VNCSpy samples (predecessor to PromptSpy) uploaded to VirusTotal from Hong Kong. Distribution domain mgardownload[.]com registered on Cloudflare.
- Four PromptSpy dropper samples uploaded to VirusTotal from Argentina. Contains embedded app-release.apk payload with Gemini AI integration.
- Google Play Protect updated to detect known PromptSpy variants. ESET shared findings with Google via App Defense Alliance partnership.
- ESET publishes full technical analysis on WeLiveSecurity. IOCs released on GitHub. Source: https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/
- Threadlinqs Intelligence Platform publishes TL-2026-0135 with full MITRE mapping, detections, and simulations.
- As of 2026-05-29, PromptSpy remains an ESET-assessed proof-of-concept never seen in telemetry, off Google Play, and now flagged by Play Protect with Google having disabled linked assets and hardening the Gemini API. No CVE, no in-the-wild campaign, takedown, or successor has emerged since the Feb-2026 disclosure, so it stays under monitoring rather than active.
Threats related to PromptSpy — First Android Malware Using Generative AI
- ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge Fivefold to 3,000+ Entries; PromptSpy Debuts as First Gemini-Powered Android Malware
- NGate Android Malware — HandyPay-Trojanized NFC Relay Variant Targets Brazilian Cardholders via Fake Rio de Prêmios Lottery and Counterfeit Google Play Lures
Detection coverage for TL-2026-0135
As of 2026-02-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0135 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.