Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securityautonomous-system-securityidentity-impersonation-fraud

Prompt injection and multimodal 'promptware' attacks against LLM-based systems

Updated 3mo agoFirst seen Feb 13, 20262 sources

Security researchers and commentators warned that attacks on LLM-based systems are evolving beyond simple “prompt injection” into a broader execution mechanism dubbed promptware, with a proposed seven-step promptware kill chain to describe how malicious instructions enter and propagate through AI-enabled applications. The core risk highlighted is architectural: LLMs treat system instructions, user input, and retrieved content as a single token stream, enabling indirect prompt injection where hostile instructions are embedded in external data sources (web pages, emails, shared documents) that an LLM ingests at inference time; the attack surface expands further as models become multimodal, allowing instructions to be hidden in images or audio.

Related academic work demonstrated a concrete multimodal variant against embodied AI using large vision-language models: CHAI (Command Hijacking Against Embodied AI), which embeds deceptive natural-language instructions into visual inputs (e.g., road signs) to influence agent behavior in scenarios including drone emergency landing, autonomous driving, and object tracking, reportedly outperforming prior attacks in evaluations. Separately, reporting on a viral “AI caricature” social-media trend framed the risk as downstream social engineering and potential LLM account takeover leading to exposure of prompt histories and employer-sensitive data; while largely hypothetical, it underscores how widespread consumer LLM use and public oversharing can increase the likelihood and impact of prompt-driven compromise paths.

Share:
Prompt injection and multimodal 'promptware' attacks against LLM-based systems
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Feb 13, 20264mo ago

Lawfare outlines a broader 'promptware kill chain' for LLM attacks

A Lawfare analysis argued that so-called prompt injection should be understood as a broader malware-like execution mechanism called 'promptware' and proposed a seven-stage kill chain for LLM and agent compromises. It cited prior demonstrations involving a malicious Google Calendar invite and an email-borne self-replicating prompt as examples of multistage compromise and recommended defense-in-depth rather than assuming prompt injection can be fully fixed.

Feb 11, 20264mo ago

Researchers introduce CHAI attacks against embodied AI systems

Academic research described a new attack class called Command Hijacking Against Embodied AI (CHAI), which embeds deceptive natural-language instructions in visual inputs such as road signs to manipulate LVLM-driven agents. The work reported tests against multiple embodied AI scenarios, including autonomous driving, drone emergency landing, aerial tracking, and a real robotic vehicle.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Malware
2 linked
Affected products
1 linked
Zoom
Organizations
3 linked
Zoom CommunicationsOpenaiGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.