PromptSpy is an Android spyware/backdoor and remote access trojan first identified by ESET and described as the first known mobile malware to invoke generative AI during runtime on a victim device. It uses Google Gemini APIs in its execution flow to analyze the visible Android user interface and determine gestures such as clicks and swipes, rather than relying solely on hardcoded interaction logic. Reporting also describes a GeminiAutomationAgent component that serializes the device UI hierarchy and parses structured responses into touch and gesture commands, enabling broader autonomous screen navigation through Android accessibility features.
Documented capabilities include capturing lockscreen PINs and passwords, listing installed applications, taking screenshots on demand, recording video without the user noticing, and providing live remote screen control over encrypted communications. Additional reporting states that PromptSpy can capture authentication inputs such as PINs or lock patterns for replay to regain access to a compromised device for follow-on exploitation.
For persistence and anti-removal, PromptSpy abuses Android accessibility permissions to keep itself pinned in recent apps and uses invisible overlays over the Stop and Uninstall buttons in Android settings so taps are intercepted and the app appears unresponsive. Some reporting also notes a multi-layered defense mechanism, an AppProtectionDetector module used to identify uninstall-button coordinates, and the ability to relaunch via Firebase Cloud Messaging when the device becomes inactive. Operators can reportedly update components remotely through command and control, including Gemini API keys and a VNC relay server.
ESET reported distribution via a fake Argentine banking-themed website at mgardownload[.]com, with malicious apps using the names MorganArg and MorganArgs to impersonate a JPMorgan Chase Argentina-themed application. ESET assessed that PromptSpy had limited real-world telemetry and might be an early-stage proof of concept, but reported one confirmed detection in Ukraine in February 2026. ESET also noted clues suggesting a Chinese-speaking development environment. Google stated that no apps containing PromptSpy were found on Google Play based on current detection, that assets associated with the activity were disabled, and that known versions are detected by Google Play Protect.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Instead of hardcoding taps for every possible screen layout, PromptSpy sends Gemini a plain language request along with a full map of everything visible on the current screen... Gemini studies that data and sends back a set of instructions describing which gestures to perform and where.
If the victim device becomes inactive, PROMPTSPY operators can utilize Firebase Cloud Messaging (FCM) to relaunch the backdoor, allowing the threat actor to continue their intrusion activity without alerting the victim.
PromptSpy carries out those actions through Android’s accessibility tools, then checks the updated screen and repeats the process until the app is confirmed locked in place.
If the victim device becomes inactive, PROMPTSPY operators can utilize Firebase Cloud Messaging (FCM) to relaunch the backdoor, allowing the threat actor to continue their intrusion activity without alerting the victim.
If the victim tries to uninstall PROMPTSPY, the malware employs its 'AppProtectionDetector' module to identify the on-screen coordinates of the 'Uninstall' button. The malware renders an invisible overlay directly over the button as a shield that silently intercepts and consumes the victim's touch events, making the button appear unresponsive to the user.
Their analysis found that the malware was distributed through a website designed to look like the Argentine branch of a major banking brand, complete with a matching app name meant to build trust with targets.
It abuses accessibility permissions to place invisible overlays directly on top of the Stop and Uninstall buttons in the app settings menu, so tapping them does nothing.
Promptspy used the Gemini API as an Android backdoor to analyze UI structure and simulate clicks, swipes, and even included a delete sabotage feature.
PROMPTSPY embeds a module called GeminiAutomationAgent that sends a serialized XML representation of the victim device’s current UI hierarchy... and parses the model’s structured JSON response into specific touch coordinates and gesture commands.
PROMPTSPY embeds a module called GeminiAutomationAgent that sends a serialized XML representation of the victim device’s current UI hierarchy... and parses the model’s structured JSON response into specific touch coordinates and gesture commands.
Later research from Google’s Threat Intelligence Group added that PromptSpy’s AI component was built with broader screen navigation goals in mind, and that attackers can update pieces of the malware, including its Gemini API keys, remotely through its command and control channel.
Promptflux : A self-morphing dropper that calls the Gemini API to periodically rewrite its own source code
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware / remote access trojan that steals information from infected phones, including lockscreen PINs and passwords, lists installed apps, captures screenshots, records video, provides live screen control, uses Android accessibility features for persistence and uninstall resistance, and queries Google Gemini at runtime to adapt screen interactions dynamically.
Android spyware / remote access trojan that steals information from infected phones, captures lockscreen PINs and passwords, lists installed apps, takes screenshots, records video, provides live screen control, uses Android accessibility services for persistence and anti-removal, and queries Google Gemini in real time to determine screen interactions.
Android malware that uses generative AI, specifically Google's Gemini, to interpret user interface elements and adapt across devices and environments without relying on hardcoded behavior.
An Android backdoor that uses a GeminiAutomationAgent module to send serialized UI hierarchy data to gemini-2.5-flash-lite, parse structured responses into touch and gesture commands, capture biometric replay artifacts, and block uninstall attempts via invisible overlays.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.