Activity timeline
AML.T0051 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 8 reports, and 19 of the 19 threats were reported in the twelve months to 2026-10.
How adversaries use it
AML.T0051 LLM Prompt Injection is catalogued by MITRE ATLAS under the Execution (ATLAS) tactic in the ATLAS matrix. Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 5 critical, 7 high, 7 medium.
Threats that use AML.T0051 most often also use T1027 Obfuscated Files or Information (10 threats), T1566 Phishing (9 threats), T1204 User Execution (7 threats), AML.T0054 LLM Jailbreak (6 threats), T1583 Acquire Infrastructure (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
4 tracked threat actors appear in the threats that use AML.T0051; the most frequent are Cleaver (2), MiniMax (2), Moonshot AI (2), StepFun (2).
Threat actors using it
Tracked threats
19 tracked threats use AML.T0051.
- Coordinated model-distillation campaign against OpenAI: 15,000+ accounts attempt to extract protected model…medium
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…medium
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…high
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…high
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Modelscritical
- China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier…high
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…high
- Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacksmedium
- Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271…critical
- Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Enables Sandbox Escape and RCE on Hostcritical
- Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…critical
- Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimihigh
- CSS Bomb Attacks: CSS-Based Trust-Boundary Bypass Leaks Webmail Passwords and Tokens (Outlook, Gmail, Yahoo…high
- CSS Bomb: JavaScript-Free CSS Keylogging and Token-Theft Attacks Against Gmail, Outlook, Yahoo Mail, AOL…high
- RovoBlast: One-Click Parameter-to-Prompt Injection in Atlassian Rovo AI Exposes Confluence, Jira, and…critical
- OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applicationsmedium
- Text-Salting Phishing Campaigns Abuse CSS-Hidden Text to Evade AI Email Security Filtersmedium
- Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat…medium
Detection coverage
Threadlinqs maintains 50 detection rules mapped to AML.T0051 (SPL 17, KQL 15, Sigma 18). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- AML.T0051.000 Direct — 1 tracked threat
- AML.T0051.001 LLM Prompt Injection: Indirect — 11 tracked threats
- AML.T0051.002 Triggered — 1 tracked threat