Rogue Agent Watch › Records › promptspy-gemini-android-agent
PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- Medium — Limited or contained harm, or high-signal capability demonstration.
Summary
In its May 2026 AI Threat Tracker, Google's Threat Intelligence Group (GTIG) described PROMPTSPY, an Android backdoor first identified by ESET. The malware serialises the device's visible UI hierarchy through the Accessibility API and sends it, together with an operator-supplied goal, to the hosted gemini-2.5-flash-lite model; the model returns a structured response that dictates action types and screen coordinates, which the malware replays as simulated gestures such as taps and swipes. ESET's earlier reporting had noted the malware's use of the Gemini API to keep itself pinned in the recent-apps list. Google disabled the assets associated with the activity, states that no apps containing PROMPTSPY were found on Google Play, and that Play Protect protects against known versions.
Impact as stated
Not quantified by sources. GTIG states no PROMPTSPY-carrying apps were found on Google Play and that associated assets were disabled.
Facts as stated by sources
- Actor
- Unknown (Unknown)
- Category
- Autonomous attack
- Models named
- gemini-2.5-flash-lite
- Model families
- Gemini (Google)
- Agentic autonomy level
- Supervised-autonomous
- Guardrail bypass
- Legitimate tool abuse
- Attack lifecycle phases
- Execution, Persistence
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- Google disabled the assets associated with this activity (GTIG).
- Google Play Protect automatically protects against known versions of PROMPTSPY (GTIG).
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- PROMPTFLUX — experimental self-modifying malware abusing the Gemini API
- PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine
Sources (2)
- Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
Google Threat Intelligence Group · Vendor report · · archived copy - PromptSpy ushers in era of Android threats using GenAI
ESET · Vendor report · no archive recorded
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "promptspy-gemini-android-agent". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/promptspy-gemini-android-agent.json — CC BY-SA 4.0.