Tag: Gemini AI

PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence
News

PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence

Cybersecurity researchers claim to have found the first Android virus that achieves persistence by abusing Google's generative artificial intelligence (AI) chatbot, Gemini, as part of its execution loop. ESET has given the virus the code name PromptSpy. The malware can take screenshots, record screen activity as video, collect device information, intercept lockscreen data, and prevent uninstallation attempts. In a report released today, ESET researcher Lukáš Štefanko stated that Gemini is used to examine the current screen and give PromptSpy detailed instructions on how to make sure the malicious app stays pinned in the list of recent apps, preventing it from being easily swiped away or eliminated by the system. Using generative AI allows the threat actors to adapt to almost any ...
Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support
News

Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support

As different hacker groups continue to weaponize the tool for accelerating various phases of the cyber attack life cycle, enabling information operations, and even conducting model extraction attacks, Google said Thursday that it had seen the North Korea-affiliated threat actor UNC2970 using its generative artificial intelligence (AI) model Gemini to conduct reconnaissance on its targets. According to a report provided to The Hacker News by Google Threat Intelligence Group (GTIG), the team profiled high-value targets and synthesized OSINT using Gemini to aid in campaign planning and reconnaissance. Target profiling for this actor involved mapping particular technical job roles and compensation information, as well as researching significant cybersecurity and military firms. This act...
Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly
News

Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly

On Wednesday, Google announced that it has identified an unidentified threat actor utilizing PROMPTFLUX, an experimental Visual Basic Script (VB Script) malware that communicates with its Gemini artificial intelligence (AI) model API to generate its own source code for enhanced obfuscation and evasion. According to a report shared with The Hacker News by Google Threat Intelligence Group (GTIG), PROMPTFLUX is written in VB Script and interacts with Gemini's API to request specific VBScript obfuscation and evasion techniques to facilitate "just-in-time" self-modification, likely to evade static signature-based detection. The innovative feature is a part of its "Thinking Robot" component, which regularly retrieves fresh code to avoid detection by querying the large language model (LLM)...