{"id":231677,"date":"2026-02-20T05:20:44","date_gmt":"2026-02-20T11:20:44","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/02\/promptspy-is-the-first-known-android-malware-to-use-generative-ai-at-runtime"},"modified":"2026-02-20T05:20:44","modified_gmt":"2026-02-20T11:20:44","slug":"promptspy-is-the-first-known-android-malware-to-use-generative-ai-at-runtime","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/02\/promptspy-is-the-first-known-android-malware-to-use-generative-ai-at-runtime","title":{"rendered":"PromptSpy is the first known Android malware to use generative AI at runtime"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/promptspy-is-the-first-known-android-malware-to-use-generative-ai-at-runtime.jpg\"><\/a><\/p>\n<p>Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google\u2019s Gemini model to adapt its persistence across different devices.<\/p>\n<p>In a report today, ESET researcher Lukas Stefanko explains how a new Android malware family named \u201cPromptSpy\u201d is abusing the Google Gemini AI model to help it achieve persistence on infected devices.<\/p>\n<p>\u201cIn February 2026, we uncovered two versions of a previously unknown Android malware family,\u201d <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/promptspy-ushers-in-era-android-threats-using-genai\/\" target=\"_blank\" rel=\"nofollow noopener\">explains ESET<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google\u2019s Gemini model to adapt its persistence across different devices. In a report today, ESET researcher Lukas Stefanko explains how a new Android malware family named \u201cPromptSpy\u201d is abusing the Google Gemini AI model to help it achieve [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,1512,6],"tags":[],"class_list":["post-231677","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode","category-mobile-phones","category-robotics-ai"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/231677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=231677"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/231677\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=231677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=231677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=231677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}