ESET researchers discovered the PromptSpy, the first known Android malware to exploit Generative AI in its execution flow. This is the first documented case of Generative AI being used in this way in malware. The attackers rely on prompts to an AI model (specifically Google’s Gemini) to maliciously manipulate the user interface. For this reason, ESET has named this malware family PromptSpy.
The malware can capture data from the lock screen, block uninstall attempts, collect device information, take screenshots, record screen activity in video format, and more. This is the second AI-based malware detected by ESET Research, following PromptLock in August 2025, the first known ransomware case to leverage AI.





