Chinese-developed malware exploits Gemini AI to lock apps, intercept passwords and record device activity across Argentina-targeted Android devices


  • PromptSpy malware uses Gemini to automate its persistence
  • The malware blocks removal through an AI-driven interface check
  • Gemini interprets screen data and returns actionable gestures

Security experts have revealed new findings on PromptSpy, an Android malware whose code contains a predefined prompt and AI configuration that is hard-coded and cannot be changed at runtime.

The malware uses Google’s Gemini to interpret elements on the screen and provide step-by-step instructions for interacting with the user interface.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top