Automatically translated.View original post

PromptSpy Malware on New Android

PromptSpy malware on the new Android. Gemini has been used to help make decisions.

When it comes to services that start with Prompt, many people might think of a convenient payout service like PromptPay or a similar service for businesses like PromptBiz, but this time there is another thing that uses the same word, but not financial services, but a new, intelligent malware.

According to a report by the website Cyber Security News, a new malware focused on attacking the Android operating system called PromptSpy. This malware has something more special than others. Google's AI or Artificial Intelligence, Gemini, has been used to help make decisions. This malware was first detected during February 10, last year, by a research team from ESET, a popular anti-malware tool developer, which the research team detected from four samples uploaded from Argentina to its website. VirusTotal, a website for monitoring computer viruses, called the detected malware the first to use such a technique that is currently detected.

In that investigation, it was discovered that the malware was spread by impersonating an application of the Argentine branch of JPMorgan Chase Bank N.A. under the name MorganArg, or "Morgan Argentina," which was spread through a closed fake website called mgardownload [.] com. The app was a forgery of the bank's login page. In the investigation, it was found that the malware had a string value written in Chinese, as well as an event manager in the Accessibility Mode implementation in Chinese, making it predictable that the hackers behind the development Probably a group of Chinese hackers, but at present there is no evidence of an epidemic yet, according to ESET's Telematry data, but out of all the infrastructure discovered, the malware has been found to be very ready to spread in the real world.

Unlike normal malware, this malware saves the Live User Interface in an XML file format and sends it to Gemini with a Hardcoded Prompt written in Natural Language to allow Gemini to analyze and make decisions based on real situations. After analysis, Gemini sends commands in the JSON file format containing the Swipe and Tap Instruction commands, the app lock commands in the most recently opened app part. (Lock App in Recent App), Pin fake apps in the Multitasking View section of the screen with the app locked out. For example, working with Gemini is a Feedback Loop. Malware sends new data to Gemini for comments every action. These are different from traditional malware that uses Harcoded commands. They often fail when working on a screen of a certain size or User. A different interface to a given one.

In addition to the Gemini implementation, the malware has also implemented the VNC (Virtual Network Computing) module to remotely control the victim's machine. It operates through communication with the AES encrypted C2 or Command and Control server. After the malware has access to the Accessibility mode, hackers can control the screen on the machine through the VNC channel. The fake application has an anti-removal system by creating a button stack with string values such as "stop," "end," "clear," and " Uninstalled "cannot be pressed. The deletion method must enter Safe Mode and delete only through Settings → Apps → MorganArg.

# Trending # Lemon 8 Howtoo # lemon 8 diary # Malware # freedomhack

3/13 Edited to

... Read moreจากประสบการณ์ในการติดตามข่าวสารความปลอดภัยไซเบอร์ มัลแวร์ PromptSpy ถือว่าเป็นมัลแวร์บน Android ที่มีความซับซ้อนและล้ำหน้ากว่าที่เคยพบเห็น เพราะมีการผสมผสานเทคโนโลยี AI เช่น Gemini ของ Google เข้าไปช่วยในการวิเคราะห์และตัดสินใจแบบเรียลไทม์ สิ่งที่น่ากังวลคือ วิธีการที่ใช้โดยมัลแวร์นี้นอกจากจะส่งข้อมูลอินเทอร์เฟซสดอย่างละเอียดไปยัง AI เพื่อรับคำสั่งแบบไดนามิกแล้ว ยังสามารถล็อกและปิดกั้นการใช้งานแอปปลอมผ่านหน้าจอหลายงาน ทำให้ผู้ใช้ไม่สามารถปิดหรือหยุดการทำงานของมันได้ง่ายๆ จากที่แนะนำในข่าว การปลอมตัวเป็นแอปธนาคาร JPMorgan Chase Branch Argentina เป็นตัวอย่างของมัลแวร์ที่พยายามหลอกล่อให้ผู้ใช้งานหลงเชื่อและป้อนข้อมูลส่วนตัวสำคัญ รวมถึงความสามารถในการควบคุมเครื่องผ่าน VNC และสร้างหน้าจอซ้อนปุ่มป้องกันการลบ ถือเป็นเทคนิคที่เพิ่มระดับความอันตรายขึ้นมาก สิ่งสำคัญสำหรับผู้ใช้ Android ที่อยากปลอดภัย คือควรติดตั้งแอปพลิเคชันจากแหล่งที่น่าเชื่อถือเท่านั้น และหมั่นตรวจสอบสิทธิ์ของแอป ในกรณีนี้ต้องระวังสิทธิ์การเข้าถึงกล้องและวิดีโอ รวมถึงการอนุญาตโหมดช่วยเหลือคนพิการ (Accessibility Mode) ที่ถูกใช้โดยมัลแวร์เพื่อลอบควบคุมเครื่อง นอกจากนี้ เมื่อมีความเสี่ยงพบแอปที่ผิดปกติ ควรบูตเครื่องใน Safe Mode และทำการลบแอปจากการตั้งค่าโดยตรง เพื่อป้องกันไม่ให้มัลแวร์ชิงปิดกั้นการลบด้วยหน้าจอซ้อนอย่างที่กล่าวมา สุดท้ายนี้ การรักษาความปลอดภัยไซเบอร์ในปัจจุบันต้องปรับตัวให้ทันเทคโนโลยีใหม่ เพราะมัลแวร์ยุคใหม่แม้จะฉลาดกว่าเดิม แต่ถ้าผู้ใช้ตระหนักถึงความเสี่ยงและรู้วิธีป้องกัน ก็ยังสามารถลดความเสียหายจากการโจมตีได้อย่างมีประสิทธิภาพ

Related posts

SOS!!! Wha do you do if you click a phishing email link… two times?!? So far I have: 1, added two factor sign on 2, changed my passwords 3, stress cried and spiraled But for real. What do you do… how do I know if there is now malware (? Is that what it’s called ?) living on my computer?!?
Alexandra Wildeson

Alexandra Wildeson

2 likes

Top Cybersecurity Certificates
There are several reputable cybersecurity certifications that can help you advance your skills and knowledge in the field of cybersecurity. 1. Certified Information Systems Security Professional (CISSP): - CISSP is a globally recognized certification that covers a wide range of cybersecurit
anjali.gama

anjali.gama

110 likes

It's no secret that Karol G just slayed the #Grammys #Glambot . #AwardsSeason
user6854050772614

user6854050772614

5 likes

💚🖤 #fyp #fypシ #fypシ゚viral #foryoupage #inspire #in
💚🖤 #fyp #fypシ #fypシ゚viral #foryoupage #inspire #inspiration #goviral #motivation #motivate #dankvisionz
Lisa Marie 💚🖤

Lisa Marie 💚🖤

6 likes

Animetober Day 2: Manga ~ Banana Fish
Ash Lynx 🟢 #bananafish #animeart #ashlynx #animedrawing #Anime
kaze.hak 🦝

kaze.hak 🦝

34 likes

Midnight Mission
🫧 Prompt will be in comments 🫧 Please tag/credit me if you use them! 🫧 Comment with your creations. I’d love to see! #ai #gemini #aiprompt #spyxfamily #assassin
🫧 Midsummer Fae

🫧 Midsummer Fae

5 likes

Why I switched to taking notes on my iPad
I used to love writing in notebooks, but after switching to my iPad, I can confidently say I’m never going back! Here’s why: ✨ Cuter Notes – Let’s be real…aesthetic notes make studying more enjoyable! I can use custom colors, cute stickers, and different handwriting styles to make my notes visua
Rebecca R.

Rebecca R.

262 likes

Check out this website that helps you when you’re feeling uninspired! I walk you thru the process of downloading the svg file to taking it to cricut design space! Happy crafting. #designinspo #creativeart #cricutprojects #svgfiles #CricutTips
VlunaWorks

VlunaWorks

30 likes

+it’s less than 80$✨❗️LINK for this item in my bio❗️
Details⬇️: This flip phone smartphone with a flip keyboard design, offering both the convenience of a traditional keypad and the functionality of a modern touchscreen device. With 4GB of internal storage, you'll have plenty of space for apps, photos, and more. The compact 3.5" displa
Atlas

Atlas

443 likes

You need TikTok ?
Here is how you can download TikTok if you need help with and apple phone just ask me I can help with Apple phone you need to change your region on the Apple Pay store
Ali

Ali

10 likes

ERROR ERROR ERROR ERROR ERROR
🔺️!!!Flashy!!!🔺️ Um guys... Something is definitely wrong with my tablet 😬😨 #rewritesonic #malware #sonicexe #sonicthehedgehog #sonicfanart
EmK & Fidgi

EmK & Fidgi

1 like

Never plug your phone or computer into usb plugs in hotels or airports here’s why 👇🏼 A USB port doesn’t just deliver power, it can also transfer data. A compromised hotel USB outlet could secretly install malware on your phone or copy your data without you realizing it. Hotels, airports, and o
Cybersecurity Girl

Cybersecurity Girl

146 likes

Just Finished!!
Finger painting is awesome!! I don’t have my brushes with me so i decided to finger paint, it’s even better than i imagined it’d turn out!! I may or may not sell this painting, but I will have lots more to share like this!! ⭐️Overall rating: 10/10 #paintingmyselfhappy #painting 🎨 #hel
✨🖤alexandria🖤✨

✨🖤alexandria🖤✨

50 likes

3 cybersecurity jobs that pay well
1. Security Analyst - What They Do: Monitor networks for vulnerabilities, investigate breaches, and implement security measures. - How to Start: - Obtain certifications like CompTIA Security+ or CySA+. - Gain experience with tools like SIEM (e.g., Splunk). - Start in an I
vedha | career tips (tech) 👩‍

vedha | career tips (tech) 👩‍

628 likes

😫 Wanting to quit your 9-5?
Becoming a Pinterest Manager might be for you! In less than a year, I went from earning $2K at my 9-5 to over $4K/month with Pinterest management alone. Now, with all the different skills and platforms I lesrned, I make anywhere from $12-15K A MONTH! Back then, I knew I had to do something
Bria | Monetize with AI 🤖

Bria | Monetize with AI 🤖

482 likes

Elite Hacker Destroyed His Empire By Forgetting On
Bro, I really forgot to use a VPN 💀 #hacker #cybercrime #fail #tech #arrestedstupidly
arrestedstupidly

arrestedstupidly

1 like

& bunch of crooks praying on people who are
#gettoknowme 219 Chicago Ave
Edward

Edward

11 likes

This video has been sitting in my drafts since 2025. Not because it wasn’t good, but because I waited for “perfect.” Just the same way we take the perfect picture and over staring at it, opens up the imperfections in the photo🤣🤣🤣 Today, I realized the message in this video still matters: persona
Abby❤️💎

Abby❤️💎

1 like

my physical sim card from my original AT&T smartphone has been stolen out of my Samsung Galaxy Fold7
Dougintime

Dougintime

4 likes

the best VPN for all your needs!
NordVPN is a great tool to have if you want to access all websites from any region! (traveling or not). It keeps your connection secure on public Wi-Fi, protecting your data from hackers. Plus, it lets you access academic resources or websites that might be restricted in certain countries if you ar
Anaïs D’Ottavio

Anaïs D’Ottavio

12 likes

#cybersecurity #studying #studytok #studywithme #BackToSchool
study with me 📚

study with me 📚

21 likes

Try this ChatGPT Prompt
I asked mine: "Based on everything you know about me, what are 10 high-leverage ways I should be using Al that I haven't thought of yet?" Here’s one of the suggestions it gave me “Automated Market Research Spy Have AI: Track local competitors’ pricing & services Analyze wha
Monica

Monica

584 likes

Back Up Outlook Emails to an External Hard Drive
Need to back up your Outlook emails to an external hard drive? Here are 2 simple methods to help you out. Download AOMEI Backupper and give it a try! #backup #outlook #externalharddrive
SmoothTechie

SmoothTechie

1 like

TwistedMexi Mod Guard
There has been some weird stiff going on with third party mod and cc domains, like Curseforge. Like they’re putting malware in your Sims. So until the issue is fixed please download TwistedMexi Mod Guard. Stay safe #sims4cc #sims4content #sims4community #sims #sims4ccfinds #simscommunit
jae

jae

11 likes

Tools and sites I use as a cybersecurity student 🌸
#cybersecuritystudent #cybersecurity #techgirlie
LexiStudies

LexiStudies

102 likes

The Easiest Way to Get Mac Premium Apps!
Why Setapp is Essential: One Subscription, Numerous Apps: Gain access to over 240 premium applications for a single monthly fee,no need for multiple subscriptions.  Effortless Search & Download: Quickly discover the ideal productivity tool with an easy search, and download it right away. Enh
Reverelia

Reverelia

19 likes

3 D Models 💙
Dropped this pic into Gemini and boom — got this cute model look! 😍✨ #GeminiApp #3DGlowUp #AIvibes #DigitalMagic #GeminiStyle #DeskBuddies #MadeWithGemini Google 💙Gemini ➡️ Prompt for couple model (see solo prompt @comment)@highlight create a 1/7 scale commercialized figure
OnTJourney

OnTJourney

1 like

Invader Zim Gir Prompt 2 💚
{ Prompt and Pics made by me. } #googlegeminiai #invaderzim #gir #invaderzimgir #kigurumi
Pengy ᓚᘏᗢ

Pengy ᓚᘏᗢ

0 likes

A series I’ve wanted to do forever! As a cyber security expert and bridal makeup artist I hope to share cyber concepts in easy to understand makeup metaphors! Let me know in the comments what topics interest you 💕 #makeupandmalware #mascara #cybersecurity @Lancôme
Betsy H

Betsy H

3 likes

productivity apps on your mac!
Proton VPN for staying secure online and Grammarly for making sure I don’t send embarrassing emails literally two apps I use daily to stay productive without the stress. If you’re not using them yet, you’re missing out! #lemon8partner #lemon8creator #tech #apps #productivity
asmae🐸

asmae🐸

19 likes

The Podcast Invite Scheme! Always remember - it’s not your fault ♥️ this happens to so many people. Most importantly: STAY SUSPICIOUS OF EVERYTHING 🥰💕 #podcastinvite #podcast #creator #storytime #scheme
Chloe

Chloe

66 likes

Indiana Mish (meesh)

Indiana Mish (meesh)

0 likes

#creatorsearchinsights #therapeutictiktok #somatichealing #storedtrauma #yellowstonetv
Rawr xD Yuna🌙The.Terror.

Rawr xD Yuna🌙The.Terror.

0 likes

🏰✨Disney Tattoos✨🏰
Did you know, I’m a HUGE Disney nerd! It’s always a treat whenever I get to do something based on Disney, small or big, flash or custom 🥰 Here’s just a small compilation of some of my favorites! #disney #disneytattoo #tattoo #tattooartist #traditionaltattoo
Malware 🔜 FC

Malware 🔜 FC

375 likes

What Character Did you Pick? 🤷🏾‍♀️🦸🏽‍♀️
Writing Prompt of the Week ✍️🏾 #writing #stories #writingtips
Zariel Pate

Zariel Pate

0 likes

Hackers hijacked antivirus features to install mal
Hackers hijacked antivirus features to install malware - here's what we know https://www.yahoo.com/tech/cybersecurity/articles/hackers-hijacked-antivirus-features-install-140500891.html #hackers #malware #cybersecurity #antivirus
angela1957

angela1957

1 like

If you’re staring at Cricut Design Space with zero ideas this is for you! This free SVG website is perfect when you need inspiration fast. Save & share with your crafty bestie 💖 #designinspo #creativeart #DesignProcess #cricutprojects #CricutTutorial
VlunaWorks

VlunaWorks

0 likes

New macOS Malware
New malware targeting macOS with an information stealer program that is designed to take your online information. #macos #cyber
Lemon8er

Lemon8er

0 likes

🧠 Would YOU plug in a random USB? Jamie did… and almost let hackers into his system. ⚠️ This comic shows a real cybersecurity trick: USB Baiting — where attackers drop infected drives hoping someone connects them. 👀 Learn what a Trojan is 🔐 Discover how to spot dangerous files 💬 Drop a 🛑
CyberSnack

CyberSnack

1 like

Recover Hidden Files from USB Using Command Prompt
Can’t see your files on a USB stick even though they’re there? This video shows how to use Command Prompt commands (like attrib) to unhide files hidden by system attributes or viruses — plus what to try if that doesn’t work. #USB #cmdanks #digitallifestyle #techtutorial #newonlemon8
XanthusTechCore

XanthusTechCore

2 likes

Malicious Android App
Cybercriminals are using fake ATT apps to distribute malware #cybersecurity #Android
Lemon8er

Lemon8er

0 likes

⚡ How to Make Your PC Run Faster – 5 Easy Tips! 🖥️🔥
💡 1. Disable Startup Programs 🚀 Too many apps launching at startup slow down your PC! ✅ Open Task Manager (Ctrl + Shift + Esc) ✅ Go to the Startup tab ✅ Disable unnecessary apps to speed up boot time 💡 2. Clean Temporary Files 🗑️ Over time, junk files slow your system down. ✅ Press Win
skaeszun

skaeszun

284 likes

This is the newest way people are getting hacked and if you use AI to answer your questions and give you advice, you need to watch this.Thanks to Huntress for reporting this Follow for more
Cybersecurity Girl

Cybersecurity Girl

15 likes

Don’t Use Airport USB Chargers!
TSA is now advising NOT to use Airport USB Chargers. Bring your own USB charging bricks. "Hackers can install malware at USB ports (we’ve been told that’s called 'juice/port jacking'). So, when you’re at an airport do not plug your phone directly into a USB port. Bring your TSA-compl
Destination & Travel Junkies

Destination & Travel Junkies

151 likes

#friends #sleepover #coolideas
Genesis

Genesis

196 likes

Revelry in the Dark
#myheroacademia #mha #bokunoheroacademia #bnha #tokoyami
Malware X20

Malware X20

5 likes

See more