Rogue Agent Watch › Records › promptspy-gemini-android-agent

PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
Medium — Limited or contained harm, or high-signal capability demonstration.

Summary

In its May 2026 AI Threat Tracker, Google's Threat Intelligence Group (GTIG) described PROMPTSPY, an Android backdoor first identified by ESET. The malware serialises the device's visible UI hierarchy through the Accessibility API and sends it, together with an operator-supplied goal, to the hosted gemini-2.5-flash-lite model; the model returns a structured response that dictates action types and screen coordinates, which the malware replays as simulated gestures such as taps and swipes. ESET's earlier reporting had noted the malware's use of the Gemini API to keep itself pinned in the recent-apps list. Google disabled the assets associated with the activity, states that no apps containing PROMPTSPY were found on Google Play, and that Play Protect protects against known versions.

Impact as stated

Not quantified by sources. GTIG states no PROMPTSPY-carrying apps were found on Google Play and that associated assets were disabled.

Facts as stated by sources

Actor
Unknown (Unknown)
Category
Autonomous attack
Models named
gemini-2.5-flash-lite
Model families
Gemini (Google)
Agentic autonomy level
Supervised-autonomous
Guardrail bypass
Legitimate tool abuse
Attack lifecycle phases
Execution, Persistence
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

None recorded upstream.

Mitigations as stated

  • Google disabled the assets associated with this activity (GTIG).
  • Google Play Protect automatically protects against known versions of PROMPTSPY (GTIG).

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (2)

  1. Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
    Google Threat Intelligence Group · Vendor report · · archived copy
  2. PromptSpy ushers in era of Android threats using GenAI
    ESET · Vendor report · no archive recorded

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "promptspy-gemini-android-agent". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/promptspy-gemini-android-agent.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction