Timeline

ESET reports first Android malware using generative AI and a doubling of ClickFix-style attacks

PromptSpy calls Google's Gemini at runtime to read and interpret a phone's screen, letting one malware sample adapt to interfaces across different devices without hardcoded rules.

  • Security & misuse
  • Minor

ESET’s H1 2026 threat report identified “PromptSpy,” described as the first known Android malware to call a generative AI model at runtime rather than relying on hardcoded logic. The malware uses Gemini to interpret what is on a phone’s screen and adjust its behaviour accordingly, letting a single sample work across different devices and interface layouts without needing device-specific code written in advance.

The finding sat inside a broader survey: ESET said it examined nearly 900,000 so-called “AI skills” — plug-ins and extensions built for AI assistants and agent platforms — over the first half of 2026, and found tens of thousands it classed as suspicious and thousands as outright malicious. The report also tracked “ClickFix”-style social engineering, in which victims are talked through running malicious commands themselves via fake CAPTCHAs, AI-branded help pages, browser extensions or cloud-authentication prompts; ESET said detections of this technique more than doubled between the second half of 2025 and the first half of 2026.

Both findings pointed to the same shift: attackers using AI tooling not just to generate phishing content but to make malware itself more adaptive, and to make social-engineering lures harder to distinguish from legitimate AI-product interfaces.