Tech
PromptSpy Android malware may exploit Gemini AI | Computer Weekly
An Android-specific malware targeting mobile device takeover appears to use generative AI (GenAI) services in its execution flows to maintain persistence on the victim’s smartphone, researchers at ESET have reported.
The raison d’être of the newly-discovered PromptSpy malware is to deploy and run a virtual network computing (VNC) module on the victim’s device, enabling attackers to capture lockscreen data, gather device information, take screenshots and record activity, and block uninstallation.
But to do so it must first establish persistence on the device, and it is here that GenAI comes into play, said the ESET team. They claimed that PromptSpy uses the onboard Google Gemini service to interpret onscreen elements and provide it with dynamic instructions on how to execute a specific gesture that will enable it to remain in the device’s recent app list. This, in theory, stops it being easily swiped away by the user or killed by the system.
ESET researcher Lukáš Štefanko said that while GenAI plays only a minor role in PromptSpy’s execution flow it could have a significant impact on the malware’s potential adaptability.
“Since Android malware often relies on UI-based navigation, leveraging generative AI enables threat actors to adapt to more or less any device, layout, or operation system version, which can greatly increase the pool of potential victims,” he said.
“Even though PromptSpy uses Gemini in just one of its features, it still demonstrates how implementing these tools can make malware more dynamic, giving threat actors ways to automate actions that would normally be more difficult with traditional scripting.”
Štefanko said that based on localisation clues and distribution vectors, PromptSpy seems to be run by a financially-motivated threat actor, exploits Morgan Chase branding, and may primarily target users in Argentina.
However, he also stressed that the malware has not yet popped up in ESET’s wider telemetry, which may suggest it is a proof of concept (PoC) at this point in time. Nor has it been observed on the Google Play store – it can only be downloaded by a dedicated website that its victims would need to be conned into visiting.
Computer Weekly understands that Štefanko’s discovery has been shared with Google via the App Defense Alliance programme, and Android users should already be automatically protected against known versions of it by the Google Play Protect service.
In the unlikely event that PromptSpy has somehow infected their device, victims can remove it by rebooting their phone into Safe Mode, which disables third-party applications and enables them to be uninstalled normally.
GenAI malwares. Hype or threat?
PromptSpy is not the first alleged malware exploiting GenAI to have been surfaced by the ESET team, which last year also discovered a ransomware – named PromptLock – which ran a locally accessible AI language model to autonomously plan, adapt and execute a ransomware attack.
PromptLock turned out to be the fruit of a research project conducted by a team of PhD and post-doctoral researchers at New York University’s (NYU’s) Tandon School of Engineering – specifically to illustrate the potential dangers of AI malwares.
Other supposed AI malwares found so far include FruitShell, which included GenAI promps to bypass detection and analysis, PromptSteal or Lamehug, a data miner linked to Russian state activity that queried a GenAI model to generate commands for execution via the Hugging Face API, and QuietVault, a credential stealer targeting GitHub and NPM tokens. Details on these malwares were published by the Google Threat Intelligence Group (GTIG) in November 2025.
However, their discovery has prompted widespread debate as to exactly how much of a threat such malwares really are, with some researchers arguing that the industry is overblowing their significance.
Tech
Border Patrol Agents Sold Challenge Coins With ‘Charlotte’s Web’ Characters in Riot Gear
US Border Patrol agents are raising money by selling coins that commemorate last year’s wave of immigration enforcement “operations” across the country, along with other merchandise. The funds are for nonprofit organizations that list Border Patrol buildings as their address in IRS paperwork. At least two of the organizations have dedicated US Customs and Border Protection email addresses.
The front side of one coin for sale reads, “NORTH AMERICAN TOUR 2025,” along with the acronyms for US Border Patrol and the acronym for “fuck around and find out”—a phrase that was initially popularized by the far-right group the Proud Boys and has been used by various Trump officials. In the center, the coin depicts a gas mask, a riot control smoke grenade, and a pepper ball launcher. On the other side, the coin appears to have a portrait of Border Patrol’s now retired commander-at-large, Gregory Bovino, with his arm raised in a salute, along with the text “COMING TO A CITY NEAR YOU!” It lists seven cities, many of which actually saw federal enforcement surges in 2025: Chicago, Los Angeles, Memphis, Phoenix, Portland, Charlotte, and Atlanta.
The coin is for sale by Willcox Morale Welfare and Recreation, a nonprofit that the IRS most recently declared tax-exempt during the Biden administration and whose address on IRS paperwork matches that of the Willcox Border Patrol Station in Arizona. A request for comment sent to Willcox MWR’s dedicated CBP email address went unanswered.
Employees of the Department of Homeland Security, the parent agency for Border Patrol, are allowed to start private, not-for-profit employee associations within DHS, so long as they get formally recognized by the agency and follow certain rules. According to DHS policies, officially recognized groups can fundraise using government property and create merchandise with the agency’s name and logos–but they have to receive advance approval from the agency.
Willcox MWR is just one of several groups across the country that cater to Border Patrol agents and refer to themselves as MWRs, a reference to the US military’s “morale, welfare and recreation” programs. The groups tend to throw holiday events and retirement parties, and sometimes raise money for the families of agents going through hard times, including those not getting paid during the current shutdown.
Many MWRs also sell customized medallions known as “challenge coins” that commemorate specific teams or events. While anyone, including CBP alumni, can design and sell coins, current DHS employees are not supposed to use government resources to sell ones that use the agency’s seals or logos without permission, or ones that the agency considers inappropriate or unprofessional.
CBP did not provide comment about its relationship to Willcox MWR or any other nonprofit mentioned in this story, nor whether the agency had green-lit the “North American Tour” coin design, ahead of publication.
Under Willcox MWR’s Facebook post about the “North American Tour” coin, someone named Juan Diego commented, “Sign up SDC BK5 MWR for 10.”
“Shoot us an email,” someone managing the Willcox MWR account replied, giving out what appeared to be a dedicated cbp.dhs.gov email address for the group.
SDC BK5 MWR, also a registered nonprofit, lists an address on its website that matches that of a government facility in Chula Vista, California. It says on its site that it was started by San Diego Sector Border Patrol agents and sells custom merchandise “designed to raise funds for morale and relief efforts.”
Diego did not respond to a request for comment.
The SDC BK5 MWR website has listings for over 200 different products in addition to the North American Tour coin. One of those listings was a “Chicago Midway Blitz” challenge coin in the shape of a gas mask that doubles as a bottle opener. Embossed around the edges of the coin are the names of several municipalities and neighborhoods caught up in DHS’s immigration enforcement surge of the same name last fall. Like the North American Tour coin, it features the US Border Patrol logo and the acronym for “fuck around and find out.” Opponents of the Trump administration’s immigration enforcement activity in Illinois are unamused.
Tech
One of Our Favorite 360 Cams Is 35 Percent Off
Tired of taking your action camera on an adventure, only to get home and find out you missed the action with a bad angle? One option is to switch to a 360-degree action cam, so you can capture all of the action and then edit down to just the good stuff later. One of our favorite options, the DJI Osmo 360, is currently available for just $390 on Amazon, a $209 discount from its usual price, and it comes with a selfie stick and an extra battery.
The DJI Osmo 360 achieves its impressive all-around video quality by leveraging a pair of 1/1.1-inch sensors, larger than some other offerings, and by supporting 10-bit color. You can really see that in the camera’s output, with colors that are vivid and bold, to the point that you may need to dial them back a bit in post if you want something more natural. With support for up to 50 frames per second at 8K when recording in 360 degrees, or 120 fps at 4K when shooting with only one sensor, you’ll have plenty of material to work with. In our testing, it ran for just shy of two hours at 30 fps, which is also around the time the internal storage had filled up anyway.
If you plan on catching any serious discussions with your Osmo 360, you’ll be pleased to know it connects directly to DJI’s line of wireless lavalier microphones, including the excellent and frequently discounted DJI Mic 2 and Mic Mini. If you want to mount it to something other than the included 1.2-meter selfie stick, it has both DJI’s magnetic attachment system and a more traditional ¼”-20 tripod mount. The DJI Mimo app lets you control the camera and adjust any settings, and there’s even a simple editor for on-the-fly production. For desktop users, DJI Studio has even more in-depth settings and editing options, in case you don’t want to pay for Premiere.
The DJI Osmo 360 is one of our favorite action cameras, and is particularly appealing at the discounted price point, but make sure to check out our full review for more info, or head over to our full roundup to see what else is available.
Tech
Artemis II: Everything We Know as Its Crew Approaches the Far Side of the Moon
On day six of its mission, Artemis II is closing in on the far side of the moon. Meanwhile, the historic journey has not been without fascinating and curious stories, from the images and videos that its four crew members have shared with the world to the inevitable unforeseen events—including a tricky toilet situation.
A few hours before the crew begins its lunar flyby, here’s how things are going on Artemis II.
When Will They Reach the Far Side of the Moon?
While Artemis II won’t actually land on the moon (that won’t happen until Artemis IV), that does not make this mission any less compelling. Once the Artemis II astronauts finish flying over the dark side of the moon, they will have the historic distinction of being the humans who have traveled the farthest from Earth.
They will also test all the systems needed for future lunar missions, validating life support, navigation, spacesuits, communications, and other human operations in deep space.
But when are they supposed to reach this far-off point? First, the Orion capsule reached what is known as the moon’s “sphere of influence” on Sunday night. This is the point where the moon’s gravitational force is stronger than the force of the Earth.
At present, Orion is circling the moon. Once the capsule is on the dark side of the moon, approximately 7,000 kilometers from the surface, communications with Earth will be interrupted. For six hours, they will be able to view the far side of the moon, something no human being has ever seen with their own eyes—not even the astronauts of the Apollo program, as this region of the moon was always too dark or difficult for them to reach.
That six-hour flyby of the dark side of the moon is expected to begin Monday, April 6, at 2:45 pm EDT and 7:45 pm London time.
After that, the capsule will use the moon’s gravity to propel itself back to Earth. Splashdown, when the astronauts reach Earth, is scheduled for April 10 in the Pacific Ocean, not far from the coast of California, the tenth day of the mission.
Remember that you can follow the live broadcast of the Artemis II mission from NASA’s official channels.
What Has Happened so Far?
Since its successful launch on April 1 from Kennedy Space Center, the Artemis II crew has shared several spectacular photos, such as the featured image in this post, which shows mission specialist Christina Koch looking down at Earth through one of Orion’s main cabin windows.
This incredible photo of a Earth, taken on April 2, went viral on social media, referencing the famous “Blue Marble” image captured by the Apollo 17 astronauts in 1972.
View of Earth taken by astronaut Reid Wiseman from the window of the Orion spacecraft after completing the translunar injection maneuver on April 2, 2026.Photograph: Reid Wiseman/NASA/Getty Images
-
Sports1 week agoUSMNT handed reality check by Doku, Belgium ahead of World Cup
-
Uncategorized4 days ago
[CinePlex360] Please moderate: “Trump signals p
-
Sports1 week ago2026 NCAA men’s hockey tournament: Schedule, results
-
Uncategorized1 week ago
[CinePlex360] Please moderate: “Further tariff
-
Entertainment3 days agoJoe Jonas shares candid glimpse into parenthood with Sophie Turner
-
Tech3 days agoOur Favorite iPad Is $50 Off
-
Entertainment1 week agoDemystifying the PTI
-
Politics7 days agoTrump considers asking Arab allies to help to pay for Iran war
