PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence

Cybersecurity researchers claim to have found the first Android virus that achieves persistence by abusing Google’s generative artificial intelligence (AI) chatbot, Gemini, as part of its execution loop.

ESET has given the virus the code name PromptSpy. The malware can take screenshots, record screen activity as video, collect device information, intercept lockscreen data, and prevent uninstallation attempts.

In a report released today, ESET researcher Lukáš Štefanko stated that Gemini is used to examine the current screen and give PromptSpy detailed instructions on how to make sure the malicious app stays pinned in the list of recent apps, preventing it from being easily swiped away or eliminated by the system.

Using generative AI allows the threat actors to adapt to almost any device, layout, or OS version, which can significantly increase the pool of possible victims because Android malware read more about PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *