TechFlow News: On February 26, GoPlus Security warned users about a new Android malware named PromptSpy. This malware lures users into downloading APK files via phishing websites—such as fake banking sites—and, once granted Accessibility Service permissions, enables remote device control. What sets PromptSpy apart is its use of the Google Gemini API to analyze the device’s user interface and dynamically formulate attack strategies. This capability allows it to better adapt to different smartphone brands and OS versions, thereby enhancing both the stealth and success rate of its attacks.
Security Recommendations:
- Avoid installing APKs from unknown sources
- Exercise caution when granting Accessibility Service permissions
- Enable Google Play Protect




