Threat actors are increasingly discussing and selling indirect prompt injection (IDPI) tools on underground forums, with generators for email, PDF, calendar invite, and webpage attack content. The activity suggests near-future abuse of hidden prompts in mail, documents, calendar invites, and malvertising to manipulate AI agents and exfiltrate data. #IndirectPromptInjection #TycoonPhaaS #OWASP
Keypoints
- Indirect prompt injection (IDPI) is being actively marketed and developed in underground criminal forums.
- Advertised subscription offerings reportedly start at about $150 per month.
- Tools are being sold to generate IDPI payloads for emails, PDFs, calendar invites, and webpages.
- Attackers are testing hidden prompt delivery methods such as white-on-white text, tiny fonts, and image alt text.
- Calendar invite abuse may let malicious prompts be processed by mail agents even without user interaction.
- Malvertising is emerging as another likely delivery method, with prompts embedded in dynamically loaded ad content.
- Proofpoint expects these experimental techniques to appear more often in real-world attack chains in the coming months.
MITRE Techniques
- [T1204.002 ] User Execution: Malicious File – Malicious prompts are embedded in files like PDFs and email content so automated processing may execute or interpret them (‘IDPI may be included in files attached to emails (PDF, DOCX) which contain instructions to a scanning agent’).
- [T1056 ] Input Capture – The technique relies on feeding crafted text into AI/mail agents so the model consumes attacker-controlled instructions (‘the prompt is contained within a website’s code but is not rendered to the user’).
- [T1189 ] Drive-by Compromise – Malicious prompts are planned for webpages and malvertising, where visiting content can trigger agent processing (‘adversaries are also planning to embed prompts inside malicious advertisements, to be dynamically loaded’).
- [T1566.002 ] Phishing: Spearphishing Link – Calendar invites and email lures are used to deliver hidden prompts and possibly links to malicious destinations (‘affiliates would often send invitations with links to landing pages designed to harvest credentials’).
- [T1036 ] Masquerading – Attack content is disguised as benign material such as normal-looking NDA samples or meeting agendas (‘The file looks clean in VirusTotal… only the IDPI’ and ‘presented as a meeting agenda’).
Indicators of Compromise
- [URLs / Web Resources ] Reference and research sources mentioned in the article – OWASP GenAI LLM Prompt Injection page, VirusTotal
- [Email Address ] Exfiltration destination embedded in the PDF prompt – [email address], and other 0 items
- [File Types ] Delivery and attachment formats used for IDPI – PDF, DOCX, XLSX, and ICS calendar invites
- [Monetization Detail ] Underground subscription pricing for the tooling – $150/month
Read more: https://www.proofpoint.com/us/blog/threat-insight/notes-underground-adversarial-prompt-injection