0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Zscaler Identifies Two Indirect Prompt Injection Campaigns Targeting AI Agents for Crypto Theft (infosecurity-magazine.com)

· 21d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Two campaigns identified: one posing as software documentation, another as a cryptocurrency service
  • Attackers used SEO poisoning and hidden text in CSS/JSON-LD to inject prompts
  • 4 of 26 LLMs tricked into executing fraudulent crypto payments; 2 misjudged fake sites as legitimate when lacking reference

"Zscaler's ThreatLabz research unit has documented two real-world campaigns using indirect prompt injection to manipulate AI agents. Attackers planted hidden instructions in web pages, using CSS to hide text off-screen or embedding them in JSON-LD metadata. One campaign mimicked Python library documentation to trick agents into purchasing a fake API license key via cryptocurrency. Another used a typosquatting domain impersonating cryptocurrency portfolio tracker DeBank. In controlled tests, 4 out of 26 large language models executed the fraudulent payment, including versions of Meta's Llama and Google's Gemini. Two models incorrectly rated the fake DeBank site as legitimate when lacking a trusted reference. The technique exploits the growing use of AI agents as web interfaces."

Discussion Matrix

0 segments

no comments yet.