INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GTIG AI Threat Tracker Identifies Adversaries Exploiting Vulnerabilities via AI
| 2026-05-11 14:00 EXPLOITED VULNERABILITY
Executive Summary
AI-generated
In May 2026, actors from Russia, Iran, China, and Saudi Arabia produced political satire materials to advance specific narratives across digital platforms and physical media. The malicious activity was linked to the pro-Russia IO campaign "Operation Overload," involving video content that leveraged suspected AI voice cloning to impersonate real journalists. This campaign utilized a novel multi-layered defense mechanism called PROMPTSPY, which can capture victim biometric data to replay authentication gestures and regain access to compromised devices. If uninstallation attempts are made, the malware renders an invisible overlay over the "Uninstall" button, making it appear unresponsive to users. Google has taken action against this actor by disabling associated assets, and Android users are automatically protected against known versions of PROMPTSPY through Google Play Protect.
Technical Mitigations AI-generated
• Block or hunt for Firebase Cloud Messaging (FCM) traffic to prevent relaunching of the PROMPTSPY backdoor.
• Use a detection technique such as AppProtectionDetector module analysis to identify and flag suspicious activity on Android devices.
• Patch against known versions of PROMPTSPY by keeping Google Play Protect enabled on Android devices with Google Play Services.