{"id":606174,"date":"2026-02-21T16:22:18","date_gmt":"2026-02-21T16:22:18","guid":{"rendered":"https:\/\/www.europesays.com\/us\/606174\/"},"modified":"2026-02-21T16:22:18","modified_gmt":"2026-02-21T16:22:18","slug":"android-malware-uses-googles-own-gemini-ai-to-adapt-in-real-time","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/606174\/","title":{"rendered":"Android malware uses Google\u2019s own Gemini AI to adapt in real time"},"content":{"rendered":"<p><img class=\"e_Gh\" decoding=\"async\" loading=\"eager\"  title=\"gemini logo november 2025 2\"  alt=\"Gemini logo on an Android phone.\" src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2025\/12\/gemini-logo-november-2025-2-scaled.jpg\"\/><\/p>\n<p>Joe Maring \/ Android Authority<\/p>\n<p>TL;DR<\/p>\n<ul>\n<li>Researchers have identified the first known Android malware to use generative AI during execution.<\/li>\n<li>The malware queries Google\u2019s Gemini model to adapt its behavior across different Android devices.<\/li>\n<li>It may be a proof-of-concept version, but it signals a shift toward more dynamic AI-assisted attacks.<\/li>\n<\/ul>\n<p><strong>Update: February 20, 2026 (05:12 PM ET): <\/strong>Following our request for comment and the publication of the original article below, a Google spokesperson provided us with the following statement:<\/p>\n<blockquote>\n<p>\u201cBased on our current detection, no apps containing this malware are found on Google Play. Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play.\u201d<\/p>\n<\/blockquote>\n<p>The ESET researchers had already shared their findings with Google, and similar assurances to those in the statement above are echoed in the report. Despite the abilities this malware demonstrates, there seems to be very little risk to Android users at this stage.<\/p>\n<p><strong>Original article: February 20, 2026 (01:19 PM ET):<\/strong> It\u2019s been a worrying week on the Android malware front. On Tuesday, we learned of <a href=\"https:\/\/www.androidauthority.com\/android-tablets-keenadu-malware-firmware-backdoor-3641651\/\" rel=\"nofollow noopener\" target=\"_blank\">tablets shipping with hidden malware<\/a> already embedded in their firmware. Now, researchers say they\u2019ve spotted something arguably more futuristic: Android malware that uses Google\u2019s own Gemini AI model during execution.<\/p>\n<p>According to a <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/promptspy-ushers-in-era-android-threats-using-genai\/\" target=\"_blank\" rel=\"nofollow noopener\">report<\/a> highlighted by <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/promptspy-is-the-first-known-android-malware-to-use-generative-ai-at-runtime\/\" target=\"_blank\" rel=\"nofollow noopener\">BleepingComputer<\/a>, ESET researchers have uncovered a new Android malware family dubbed PromptSpy. Unlike traditional malware that relies entirely on hardcoded instructions, this strain queries Google\u2019s Gemini <a href=\"https:\/\/www.androidauthority.com\/5-reasons-i-hate-generative-ai-features-on-my-smartphone-3556043\/\" rel=\"nofollow noopener\" target=\"_blank\">generative AI<\/a> model at runtime to help it carry out part of its behavior. In this case, the malware sends Gemini information about what\u2019s currently visible on the infected device\u2019s screen and asks for guidance on what to do next. That allows it to adapt to differences between Android devices and interfaces, rather than relying on a rigid script that might only work on certain models.<\/p>\n<p><strong>Don\u2019t want to miss the best from Android Authority?<\/strong><\/p>\n<p><a href=\"https:\/\/andauth.co\/AAGooglePreferredSource\" class=\"e_2m\" target=\"_blank\" rel=\"noreferrer nofollow noopener\"><img class=\"e_Gh\" decoding=\"async\" loading=\"lazy\"  title=\"google preferred source badge light@2x\"  alt=\"google preferred source badge light@2x\" src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2025\/09\/google_preferred_source_badge_light@2x.png\"\/><img class=\"e_Gh\" decoding=\"async\" loading=\"lazy\"  title=\"google preferred source badge dark@2x\"  alt=\"google preferred source badge dark@2x\" src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2025\/09\/google_preferred_source_badge_dark@2x.png\"\/><\/a><\/p>\n<p>ESET says this is the first known example of Android malware integrating generative AI directly into its execution flow. While the AI component is used for only one feature in this example, it shows how attackers can leverage publicly available AI tools to make malware more flexible and harder to design against.<\/p>\n<p>Beyond the disturbing AI development, PromptSpy functions as spyware. It reportedly includes a built-in remote access module and can collect information such as installed apps and lockscreen credentials once it gains the necessary permissions. It also attempts to make removal more difficult by interfering with efforts to disable it.<\/p>\n<p>So far, ESET says it hasn\u2019t observed PromptSpy or its dropper in its telemetry, making it unclear whether the malware is actively spreading or remains closer to a proof-of-concept. However, researchers noted that the samples were distributed via a dedicated domain and impersonated a major bank, suggesting they may not be purely experimental.<\/p>\n<p>Even if its reach and scope are limited for now, the broader takeaway is hard to ignore. Generative AI isn\u2019t just being used to create malicious content \u2014 it\u2019s starting to shape how malware behaves in real time. Attackers using Google\u2019s own AI tools against Android in this instance only adds to the concern, and we have reached out to Google for comment on the matter. We will update this article with any response we receive.<\/p>\n<p>Thank you for being part of our community. Read our\u00a0<a class=\"c-link\" href=\"https:\/\/www.androidauthority.com\/android-authority-comment-policy\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-stringify-link=\"https:\/\/www.androidauthority.com\/android-authority-comment-policy\/\" data-sk=\"tooltip_parent\">Comment Policy<\/a> before posting.<\/p>\n","protected":false},"excerpt":{"rendered":"Joe Maring \/ Android Authority TL;DR Researchers have identified the first known Android malware to use generative AI&hellip;\n","protected":false},"author":3,"featured_media":606175,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[7],"tags":[691,16208,51658,158,67,132,68],"class_list":["post-606174","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ai","tag-google-gemini","tag-malware","tag-technology","tag-united-states","tag-unitedstates","tag-us"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@us\/116109544598455096","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/606174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=606174"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/606174\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/606175"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=606174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=606174"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=606174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}