PromptSpy — First Android Malware Using Generative AI (Gemini) for Context-Aware UI Manipulation, VNC Remote Access, Chase Bank Impersonation

PromptSpy — First Android Malware Using Generative AI (TL-2026-0135) is a high-severity malware campaign, first published 2026-02-23. It carries a reported China nexus and is not formally attributed, maps to 19 MITRE ATT&CK techniques (T1398, T1406.002, T1417.001), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0135

Threat ID
TL-2026-0135
Severity
HIGH
Status
MONITORING
Category
MALWARE
First published
2026-02-23
Last reviewed
2026-02-23
Attribution confidence
NONE
Nation-state nexus
China
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
20

Malware and tooling in PromptSpy — First Android Malware Using Generative AI

Malware and tooling: PromptSpy

ESET researchers discovered PromptSpy, the first known Android malware to abuse generative AI (Google Gemini) in its execution flow. The malware sends Gemini natural-language prompts with XML dumps of the current screen to dynamically navigate UI and achieve persistence across any device, layout, or OS version. Its primary payload deploys a VNC module for full remote device access with AES-encrypted C2 communication.

How PromptSpy — First Android Malware Using Generative AI works

PromptSpy represents a paradigm shift in mobile malware — the first Android threat to incorporate generative AI (Google Gemini) directly into its execution flow. Discovered by ESET in February 2026, this malware family demonstrates how attackers can leverage large language models to create adaptive, device-agnostic malware that breaks free from the limitations of hardcoded UI automation scripts.

The malware operates as a two-stage dropper architecture. The PromptSpy dropper (distributed via mgardownload[.]com) installs the core payload (app-release.apk) which contains the malicious VNC and AI capabilities. Upon installation, the dropper displays a fake Chase Bank (JPMorgan Chase N.A.) website hosted on m-mgarg[.]com, branded as "MorganArg" — likely targeting Argentine users with a financial services lure.

The AI-powered component works through a continuous feedback loop: PromptSpy uses Accessibility Services to open the Recent Apps screen and collects a detailed XML dump of all visible UI elements including text, content descriptions, class names, package names, and screen bounds. This XML snapshot is sent to Google's Gemini API along with hardcoded natural-language prompts instructing the AI to analyze the UI and return JSON-formatted step-by-step instructions for performing the "lock app in recent apps" gesture. The malware executes these instructions via Accessibility Services, sends the updated screen state back to Gemini, and continues until Gemini confirms the app is successfully locked. This AI-driven approach replaces traditional hardcoded tap coordinates and UI selectors, making the malware resilient to UI changes across different devices, manufacturers, and Android versions.

The primary malicious capability is a built-in VNC module that gives operators full remote access to compromised devices — real-time screen viewing and complete device control including taps, swipes, gestures, and text input. C2 communication uses the VNC protocol over a hardcoded server (54.67.2[.]84) with AES encryption using a hardcoded key. Through this channel, the malware receives Gemini API keys, uploads installed app lists, intercepts lockscreen PINs/passwords, captures pattern unlock screens as video recordings, reports screen state and foreground apps, records screen activity for server-specified apps, and takes screenshots on demand.

Anti-removal capabilities exploit Accessibility Services to overlay transparent rectangles on screen areas containing buttons with substrings like "stop", "end", "clear", and "Uninstall" — invisible to users but intercepting all touch interactions on those elements. The only removal method is rebooting into Safe Mode where third-party apps are disabled.

The predecessor VNCSpy appeared on VirusTotal on January 13, 2026 (uploaded from Hong Kong) with three samples. Four PromptSpy dropper samples appeared on February 10, 2026 from Argentina. A companion phishing app (Android/Phishing.Agent.M) shares the same distribution domain, app name, icon, and developer certificate, likely serving as an initial stage leading victims to install PromptSpy.

Development artifacts include debug strings in simplified Chinese and handling for Chinese Accessibility event types, suggesting development in a Chinese-speaking environment. ESET classifies this with medium confidence. This is ESET's second AI-powered malware discovery after PromptLock ransomware (August 2025), the first known case of AI-driven ransomware.

PromptSpy has not been observed in ESET telemetry yet, possibly indicating proof-of-concept status, but the existence of distribution domains and companion apps suggests active development toward deployment. Android users with Google Play Protect enabled are automatically protected against known versions.

MITRE ATT&CK techniques used in TL-2026-0135

Persistence

T1398 Boot or Logon Initialization Scripts; T1541 Foreground Persistence

Defense Evasion

T1406.002 Obfuscated Files or Information: Software Packing; T1516 Input Injection; T1629.001 Impair Defenses: Prevent Application Removal; T1655 Masquerading

Credential Access

T1417.001 Input Capture: Keylogging; T1417.002 Input Capture: GUI Input Capture

discovery

T1418 Software Discovery

Discovery

T1426 System Information Discovery

Initial Access

T1476 Deliver Malicious App via Other Means; T1660 Phishing

Collection

T1512 Video Capture; T1513 Screen Capture; T1636 Protected User Data

Command and Control

T1521.001 Encrypted Channel: Symmetric Cryptography; T1663 Remote Access Software

Execution

T1575 Native API

Exfiltration

T1646 Exfiltration Over C2 Channel

Timeline of PromptSpy — First Android Malware Using Generative AI

  • ESET discovers PromptLock, the first known AI-powered ransomware — predecessor in ESET's AI malware research series.
  • Dr.WEB discovers Android.Phantom using TensorFlow ML models for ad fraud — prior art for ML in Android malware (not GenAI).
  • Phishing domain m-mgarg[.]com first seen, hosted on Amazon AWS (52.222.205[.]45). Impersonates Chase Bank for Argentine users.
  • Three VNCSpy samples (predecessor to PromptSpy) uploaded to VirusTotal from Hong Kong. Distribution domain mgardownload[.]com registered on Cloudflare.
  • Four PromptSpy dropper samples uploaded to VirusTotal from Argentina. Contains embedded app-release.apk payload with Gemini AI integration.
  • Google Play Protect updated to detect known PromptSpy variants. ESET shared findings with Google via App Defense Alliance partnership.
  • ESET publishes full technical analysis on WeLiveSecurity. IOCs released on GitHub. Source: https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/
  • Threadlinqs Intelligence Platform publishes TL-2026-0135 with full MITRE mapping, detections, and simulations.
  • As of 2026-05-29, PromptSpy remains an ESET-assessed proof-of-concept never seen in telemetry, off Google Play, and now flagged by Play Protect with Google having disabled linked assets and hardening the Gemini API. No CVE, no in-the-wild campaign, takedown, or successor has emerged since the Feb-2026 disclosure, so it stays under monitoring rather than active.

Threats related to PromptSpy — First Android Malware Using Generative AI

Detection coverage for TL-2026-0135

As of 2026-02-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0135 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats