PromptSpy is an Android remote-access trojan and spyware family that uses Google Gemini during execution to interpret a device’s visible user-interface hierarchy and obtain gesture instructions for automated screen navigation. It sends screen-layout information to the model and executes returned tap and swipe actions through Android Accessibility services, allowing its operators to interact with devices without relying exclusively on device-specific hardcoded automation.
The malware can capture lock-screen PINs and passwords, enumerate installed applications, capture screenshots, record video, and provide live remote screen control over encrypted communications. It uses Accessibility permissions to establish persistence by keeping itself present in the recent-apps list and impedes removal by placing invisible overlays over Android controls used to stop or uninstall applications. It can also capture authentication input for replay against a locked device, receive remote configuration updates including Gemini API credentials and remote-access relay settings, and be relaunched through cloud messaging.
PromptSpy was distributed through a fraudulent banking-themed Android application download site impersonating a financial institution’s Argentine operation. Public reporting indicated limited deployment at the time of discovery, including a confirmed detection in Ukraine in February 2026. Development artifacts suggested a Chinese-speaking development environment, but no threat-actor attribution has been established. Known versions were not identified on Google Play, and Google Play Protect detects known samples.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Instead of hardcoding taps for every possible screen layout, PromptSpy sends Gemini a plain language request along with a full map of everything visible on the current screen... Gemini studies that data and sends back a set of instructions describing which gestures to perform and where.
If the victim device becomes inactive, PROMPTSPY operators can utilize Firebase Cloud Messaging (FCM) to relaunch the backdoor, allowing the threat actor to continue their intrusion activity without alerting the victim.
PromptSpy carries out those actions through Android’s accessibility tools, then checks the updated screen and repeats the process until the app is confirmed locked in place.
If the victim device becomes inactive, PROMPTSPY operators can utilize Firebase Cloud Messaging (FCM) to relaunch the backdoor, allowing the threat actor to continue their intrusion activity without alerting the victim.
If the victim tries to uninstall PROMPTSPY, the malware employs its 'AppProtectionDetector' module to identify the on-screen coordinates of the 'Uninstall' button. The malware renders an invisible overlay directly over the button as a shield that silently intercepts and consumes the victim's touch events, making the button appear unresponsive to the user.
Their analysis found that the malware was distributed through a website designed to look like the Argentine branch of a major banking brand, complete with a matching app name meant to build trust with targets.
It abuses accessibility permissions to place invisible overlays directly on top of the Stop and Uninstall buttons in the app settings menu, so tapping them does nothing.
Promptspy used the Gemini API as an Android backdoor to analyze UI structure and simulate clicks, swipes, and even included a delete sabotage feature.
PROMPTSPY embeds a module called GeminiAutomationAgent that sends a serialized XML representation of the victim device’s current UI hierarchy... and parses the model’s structured JSON response into specific touch coordinates and gesture commands.
PROMPTSPY embeds a module called GeminiAutomationAgent that sends a serialized XML representation of the victim device’s current UI hierarchy... and parses the model’s structured JSON response into specific touch coordinates and gesture commands.
Later research from Google’s Threat Intelligence Group added that PromptSpy’s AI component was built with broader screen navigation goals in mind, and that attackers can update pieces of the malware, including its Gemini API keys, remotely through its command and control channel.
Promptflux : A self-morphing dropper that calls the Gemini API to periodically rewrite its own source code
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a prior example of Android malware using Gemini to interpret screen layouts and provide tap instructions.
“PromptSpy’s execution flow (Source – ESET)”
Android backdoor that uses the Gemini API to navigate autonomously.
Android spyware / remote access trojan that steals information from infected phones, captures lockscreen PINs and passwords, lists installed apps, takes screenshots, records video, provides live screen control, uses Android accessibility services for persistence and anti-removal, and queries Google Gemini in real time to determine screen interactions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.