PromptSpy malware with AI for Android

ESET researchers discovered the PromptSpy, the first known Android malware to exploit Generative AI in its execution flow. This is the first documented case of Generative AI being used in this way in malware. The attackers rely on prompts to an AI model (specifically Google’s Gemini) to maliciously manipulate the user interface. For this reason, ESET has named this malware family PromptSpy.

The malware can capture data from the lock screen, block uninstall attempts, collect device information, take screenshots, record screen activity in video format, and more. This is the second AI-based malware detected by ESET Research, following PromptLock in August 2025, the first known ransomware case to leverage AI.

See more articles from iGuRu.gr when you search for news on Google.

Based on language localization evidence and distribution channels identified during the analysis, the campaign appears to be financially motivated and primarily targets users in Argentina. However, PromptSpy has not yet been recorded in ESET telemetry, suggesting that this may be a proof of concept.

Although genetic AI is used only in a relatively small part of PromptSpy’s code – specifically in the part that deals with achieving resilience – its contribution is crucial to the malware’s adaptability. Specifically, Gemini is used to provide PromptSpy with detailed instructions on how to “lock” the malicious application, i.e. pin it to the list of recent applications (often represented by a padlock icon in the multitasking view of many Android launchers), thus preventing it from being easily deleted or terminated from the system. The AI ​​model and the associated prompt are predefined in the code and cannot be modified.

“Since Android malware often relies on user interface navigation, leveraging genetic AI allows attackers to adapt to almost any device, layout, or OS version, which can significantly increase the number of potential victims,” says ESET researcher Lukáš Štefanko, who discovered PromptSpy.

“The main purpose of PromptSpy is to deploy an embedded VNC module, which provides operators with remote access to the victim’s device. This Android malware also abuses Accessibility Services to prevent its uninstallation via invisible overlays. It also records lock screen data and screen activity in video format, while communicating with the Command & Control server via AES encryption,” adds Štefanko.

PromptSpy is distributed via a dedicated website and has never been available on Google Play. As a partner of the App Defense Alliance, ESET shared its findings with Google. Android users are automatically protected from known versions of this malware through Google Play Protect, which is enabled by default on Android devices with Google Play Services.

“Although PromptSpy uses Gemini in only one of its functions, it demonstrates how leveraging such tools can make malware more powerful, giving attackers the ability to automate actions that would normally be more difficult to implement,” concludes Štefanko.

With the app’s name MorganArg and its icon seemingly inspired by Morgan Chase, the malware is likely impersonating the bank. MorganArg, likely an abbreviation for “Morgan Argentina,” also appears as the name of the cached website, suggesting a focus on a specific geographic region.

Because PromptSpy prevents uninstallation by overlaying invisible elements on the screen, the only way to remove it is to restart the device in safe mode. In safe mode, third-party applications are disabled, allowing them to be uninstalled normally.

To enter safe mode, users typically need to press and hold the power button, then long-press the power off option, and confirm the prompt to reboot into safe mode. The exact process may vary depending on the device and manufacturer. After the phone reboots into safe mode, the user can go to Settings → Apps → MorganArg and uninstall it without any hassle.

For a more detailed analysis of PromptSpy, see ESET Research's latest blog post PromptSpy ushers in the era of Android threats using GenAI on WeLiveSecurity.com.

PromptSpy – Invisible rectangles (shown in color for clarity) that cover specific keys.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).