Executive Summary
In February 2026, ESET researchers discovered PromptSpy, the first known Android malware to utilize generative AI during its execution. This malware leverages Google's Gemini AI to interpret on-screen elements dynamically, enabling it to adapt its behavior across various Android devices and maintain persistence by preventing uninstallation. PromptSpy is distributed through a malicious dropper disguised as a system update, primarily targeting Spanish-speaking users in South America, especially Argentina. Once installed, it abuses Accessibility Services to monitor and control the user interface, deploys a Virtual Network Computing (VNC) module for remote access, and captures sensitive data such as lockscreen credentials and screen activity. (eset.com)
The emergence of PromptSpy signifies a pivotal shift in mobile cybersecurity, illustrating how threat actors are integrating generative AI to enhance malware adaptability and persistence. This development underscores the urgent need for advanced detection mechanisms and proactive security measures to counteract AI-driven threats in the evolving cyber landscape.
Why This Matters Now
The discovery of PromptSpy highlights the escalating use of generative AI in cyber threats, marking a new era where malware can dynamically adapt and evade traditional security measures. This trend necessitates immediate attention to bolster defenses against increasingly sophisticated AI-driven attacks.
Attack Path Analysis
Attackers initiated the campaign by leveraging AI-generated phishing emails to deceive users into providing credentials. Upon obtaining access, they escalated privileges by exploiting misconfigured IAM roles. They then moved laterally across cloud environments using compromised credentials. For command and control, they established encrypted channels to evade detection. Data exfiltration was conducted by transferring sensitive information to external servers. Finally, the attackers deployed ransomware to encrypt critical data, demanding payment for decryption.
Kill Chain Progression
Initial Compromise
Description
Attackers used AI-generated phishing emails to deceive users into providing credentials.
MITRE ATT&CK® Techniques
Obtain Capabilities: Artificial Intelligence
User Execution: Malicious Copy and Paste
Spearphishing Link
Phishing
Masquerade as Legitimate Application
Impair Defenses: Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Multi-vector campaigns targeting AI systems, encrypted traffic vulnerabilities, and ransomware with EDR killers pose critical risks to financial infrastructure and regulatory compliance.
Health Care / Life Sciences
AI-powered malware like PromptSpy and expanding attack surfaces through AI skills threaten patient data security and HIPAA compliance requirements significantly.
Information Technology/IT
Cloud-native security fabric vulnerabilities, Kubernetes security gaps, and shadow AI risks create substantial exposure for IT infrastructure and service providers.
Telecommunications
East-west traffic security weaknesses and encrypted communication vulnerabilities enable lateral movement attacks targeting critical telecommunications infrastructure and customer data.
Sources
- ESET Threat Report H1 2026https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/Verified
- ESET Research discovers PromptSpy, the first Android threat to use generative AIhttps://www.eset.com/us/about/newsroom/research/eset-research-discovers-promptspy-first-android-threat-using-genai/Verified
- Android malware uses Google’s own Gemini AI to adapt in real timehttps://www.androidauthority.com/android-malware-promptspy-uses-generative-ai-gemini-3642832/Verified
- PromptSpy Android malwarehttps://www.broadcom.com/support/security-center/protection-bulletin/promptspy-android-malwareVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent credential compromise, it could likely limit the attacker's ability to exploit these credentials to access sensitive workloads.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit the attacker's ability to escalate privileges by enforcing strict access controls and minimizing trust relationships.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely limit lateral movement by enforcing strict segmentation and monitoring intra-cloud communications.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely limit the establishment of unauthorized command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit data exfiltration by controlling and monitoring outbound data transfers.
While Aviatrix CNSF may not prevent the initial deployment of ransomware, it could likely limit the spread and impact by containing the attack within segmented workloads.
Impact at a Glance
Affected Business Functions
- Mobile Banking Applications
- Mobile Payment Systems
- Customer Account Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive user data, including login credentials, personal identification information, and financial details, due to remote access capabilities and screen recording features of the malware.
Recommended Actions
Key Takeaways & Next Steps
- • Implement advanced phishing detection mechanisms to identify AI-generated phishing attempts.
- • Regularly audit and properly configure IAM roles to prevent privilege escalation.
- • Enforce strict access controls and monitor for anomalous lateral movement within cloud environments.
- • Deploy network security solutions capable of detecting and blocking unauthorized encrypted communications.
- • Establish comprehensive data loss prevention strategies to monitor and control data exfiltration activities.



