Two newly documented campaigns suggest AI is moving from attacker helper to autonomous operator. GTG-1002 reportedly used AI agents to handle 80%-90% of its espionage tasks, while AI-powered Android spyware PromptSpy uses AI to adapt its attacks based on what appears on a victim's screen. Together, they show a shift that matters to ordinary phone users, not just governments and large companies.

This post breaks down what the reporting says, what remains unclear, and which defenses are realistic for everyday mobile users.

What GTG-1002 and PromptSpy actually did

According to the source reporting, GTG-1002 used AI agents for 80%-90% of espionage tasks. The important point is not the exact percentage but the division of labor: the AI handled most of the routine operational work, which suggests human operators may be needed only for oversight and key decisions. The source summary does not go into further detail, so we will not speculate about targets or tooling.

PromptSpy sits at the other end of the spectrum. It is an Android threat that uses AI to adapt its behavior based on screen content. Rather than following a fixed script, it reads what is in front of it and adjusts.

The common thread is autonomy. Traditional malware does what its authors hard-coded in advance. These campaigns point toward attacks that make decisions on the fly, which can make them more flexible and harder to predict.

This fits a broader pattern. Earlier coverage described how Chinese hackers used open-source AI in a Taiwan attack and how North Korean hackers turned to AI for smarter cyberattacks. GTG-1002 and PromptSpy add two more data points.

How PromptSpy adapts to what's on your screen

Most mobile malware breaks when the interface changes. A button moves, a menu is renamed, a phone maker uses a different layout, and a scripted attack fails. Screen-aware AI changes that equation.

Based on the reporting, PromptSpy uses AI to interpret screen content and then decide how to proceed. In practical terms, that means the malware does not need to know in advance exactly what your device looks like. It can look at what is displayed and work out the next step, much as a person would.

This matters for a few reasons:

  • Fewer device-specific limits. An attack that adapts can work across different phones, Android versions, and app layouts.
  • Harder pattern matching. Defenders often rely on recognizing repeated, predictable behavior. Adaptive behavior can vary from device to device.
  • Abuse of trust. Attacks that react to what you see can blend in with normal interface elements, which is why the theme of digital trust abuse runs through this story.

It is worth being clear about what we do not know. The source material is brief, and we cannot confirm how widely PromptSpy has spread or how many people are affected. Treat it as an early signal of where attacks are heading rather than proof of a mass outbreak.

Where a VPN helps and where it doesn't

VPNs come up in nearly every privacy conversation, so it is worth being precise. A VPN encrypts your traffic between your device and the VPN server and hides your IP address from sites you visit. That is useful on public Wi-Fi and for limiting some kinds of tracking.

But a VPN does not stop malware that is already running on your phone. Spyware that reads your screen operates on the device itself, after your traffic has been decrypted for you to view. A VPN cannot see what an app is doing with screen content, and it cannot remove a malicious app.

Where a VPN can still contribute is at the edges: protecting traffic on untrusted networks and reducing exposure to some network-level snooping. Think of it as one layer, not a shield against adaptive, on-device threats.

Practical mobile defenses against adaptive threats

Because AI-driven attacks respond to what is on screen, your best defenses focus on limiting what a malicious app can reach in the first place.

  • Audit installed apps. Remove anything you no longer use or do not recognize.
  • Review permissions. Be especially skeptical of apps requesting accessibility access or the ability to draw over other apps. Screen-reading behavior often depends on powerful permissions like these.
  • Install apps from official stores only. Avoid sideloading files sent through messages, links, or unfamiliar websites.
  • Keep your phone updated. Security patches close the gaps attackers rely on. The speed of modern campaigns is a theme in our report on CISA's 3-day patch order.
  • Use a reputable mobile security scanner and keep built-in protections such as Google Play Protect turned on.
  • Be cautious with unexpected prompts. If a screen asks you to approve something you did not initiate, stop and back out.

What This Means For You

For most people, the takeaway is not panic but a small change in mindset. Attacks are becoming more automated and more adaptive, which means the cost of targeting ordinary users is dropping. Rising attack volume is already visible elsewhere, as in the reported doubling of ransomware attacks in July 2026.

You cannot out-click an AI agent, but you can shrink the surface it has to work with. Fewer apps, tighter permissions, and prompt updates matter more than any single tool. GTG-1002 also suggests that state-linked operators are using AI to scale up, so journalists, activists, and people in sensitive roles should be especially careful.

Key takeaways

AI-powered Android spyware PromptSpy shows that malware can now read a screen and adapt, while GTG-1002 reportedly shows AI agents handling most of an espionage operation. Neither story means your phone is compromised today, but both are good reasons to act.

  1. Audit your installed apps and remove what you do not need.
  2. Check permissions, especially accessibility and overlay access.
  3. Stick to official app stores and keep your device updated.
  4. Treat a VPN as one layer among several, not a cure-all.

For broader context on how state-linked groups are adopting these tools, read our coverage of AI-enabled attacks by North Korean hackers, then spend ten minutes going through your phone's app list and permissions today.