216.73.216.226

Android threats using GenAI usher in a new era

· Published 19/02/2026 20:16 · Modified 20/02/2026 13:13

Export JSON

Essential information

Published
19/02/2026 20:16
Modified
20/02/2026 13:13
Tags
2026-02-19 accessibility service android argentina gemini generative ai promptspy remote access vnc vncspy
Related entities
1 observables, 2 malware, 4 others

Description

ESET researchers have discovered , the first known malware to abuse in its execution flow. This malware uses Google's AI to analyze screen content and provide instructions for UI manipulation, allowing it to adapt to various devices and layouts. 's main purpose is to deploy a module for to the victim's device. It also abuses the to block uninstallation, captures lockscreen data, and records video. The campaign appears to target users in and was likely developed in a Chinese-speaking environment. demonstrates how incorporating AI tools can make malware more dynamic and capable of real-time decision-making, potentially expanding the pool of potential victims.

External references