GoPlus Security has disclosed that a new type of Android malware called PromptSpy is exploiting AI technology to remotely control victims' devices. This malware typically tricks users into downloading APK files not available on Google Play through fake banking phishing websites, then requests "install unknown sources" permissions to implant the core payload. The key feature of PromptSpy is calling the Google Gemini API to send the device's current UI XML structure to a large model for analysis, with AI providing real-time operational commands to carry out malicious control. GoPlus recommends users avoid installing APKs from unknown sources, be cautious when granting accessibility permissions, and enable Google Play protection mechanisms.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
GoPlus Security has disclosed that a new type of Android malware called PromptSpy is exploiting AI technology to remotely control victims' devices. This malware typically tricks users into downloading APK files not available on Google Play through fake banking phishing websites, then requests "install unknown sources" permissions to implant the core payload. The key feature of PromptSpy is calling the Google Gemini API to send the device's current UI XML structure to a large model for analysis, with AI providing real-time operational commands to carry out malicious control. GoPlus recommends users avoid installing APKs from unknown sources, be cautious when granting accessibility permissions, and enable Google Play protection mechanisms.