home.social

#promptspy — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #promptspy, aggregated by home.social.

fetched live
  1. "ESET researchers uncovered the first known case of Android malware abusing generative AI for context-aware user interface manipulation. While machine learning has been used to similar ends already – just recently, researchers at Dr.WEB found Android.Phantom, which uses TensorFlow machine learning models to analyze advertisement screenshots and automatically click on detected elements for large scale ad fraud – this is the first time we have seen generative AI deployed in this manner. Because the attackers rely on prompting an AI model (in this instance, Google’s Gemini) to guide malicious UI manipulation, we have named this family PromptSpy. This is the second AI powered malware we have discovered – following PromptLock in August 2025, the first known case of AI-driven ransomware.

    While generative AI is deployed only in a relatively minor part of PromptSpy's code – that responsible for achieving persistence – it still has a significant impact on the malware's adaptability. Specifically, Gemini is used to analyze the current screen and provide PromptSpy with step-by-step instructions on how to ensure the malicious app remains pinned in the recent apps list, thus preventing it from being easily swiped away or killed by the system. The AI model and prompt are predefined in the code and cannot be changed. Since Android malware often relies on UI navigation, leveraging generative AI enables the threat actors to adapt to more or less any device, layout, or OS version, which can greatly expand the pool of potential victims.

    The main purpose of PromptSpy is to deploy a built-in VNC module, giving operators remote access to the victim’s device. This Android malware also abuses the Accessibility Service to block uninstallation with invisible overlays, captures lockscreen data, records video. It communicates with its C&C server via the VNC protocol, using AES encryption."

    welivesecurity.com/en/eset-res

    #CyberSecurity #PromptSpy #AI #GenerativeAI #Android #Malware

  2. CYBERCRIME QUIZ WEEK 8 - TEST JE KENNIS!

    PromptSpy, ClickFix, 600 gehackte firewalls en een babbeltruc in Breda. Weet jij alles? Test het in 20 vragen!

    ccinfo.nl/menu-onderwijs-ontwi

    #cybercrime #quiz #cybersecurity #PromptSpy #ransomware #Nederland

  3. NB406: PROMPTSPY KAPT JE ANDROID EN 90% RANSOMWARE VIA JE FIREWALL

    ClickFix in vier varianten, PromptSpy besmet Android via Gemini AI, Odido-soap groeit, cepezed gehackt en 90% ransomware begint bij je firewall.

    ccinfo.nl/menu-nieuws-trends/n

    #Nieuwsbrief #ccinfo #cybersecurity #PromptSpy #ClickFix #ransomware #Nederland

  4. PROMPTSPY, CEPEZED GEHACKT EN 90% RANSOMWARE VIA FIREWALLS

    ESET onthulde PromptSpy, de eerste malware voor Android die Google Gemini AI misbruikt. Op ClawHub werden 1.184 kwaadaardige skills ontdekt. cepezed op leksite DragonForce. Barracuda: 90% ransomware begint bij firewalls.

    ccinfo.nl/journaal/3018896_pro

    #Cyberjournaal #ccinfo #PromptSpy #cepezed #DragonForce #Barracuda #ransomware #VoltTyphoon #cybersecurity #Nederland #Belgie