# AML.T0051.001 LLM Prompt Injection: Indirect

> As of 2026-10-05, AML.T0051.001 (LLM Prompt Injection: Indirect) appears in 11 tracked threats, first reported 2026-03-12 and most recently 2026-09-27, with linked actors including Jade Sleet; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 11 (2 critical, 7 high, 2 medium)
- **First seen:** 2026-03-12
- **Last seen:** 2026-09-27
- **Threat actors:** 1
- **Detection rules:** 19 (counts only; Blue tier and above)

## Key facts

- **ID:** AML.T0051.001
- **Framework:** MITRE ATLAS
- **Tactics:** Execution (ATLAS)
- **Matrix:** ATLAS
- **Parent:** AML.T0051
- **Data as of:** 2026-10-05

## Activity timeline

AML.T0051.001 first appeared in tracked threats on 2026-03-12 and was most recently reported on 2026-09-27. The busiest month was 2026-08 with 4 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

AML.T0051.001 LLM Prompt Injection: Indirect is catalogued by MITRE ATLAS under the Execution (ATLAS) tactic in the ATLAS matrix, as a sub-technique of [AML.T0051 LLM Prompt Injection](https://intel.threadlinqs.com/technique/AML.T0051). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 2 critical, 7 high, 2 medium.

Threats that use AML.T0051.001 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (5 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (5 threats), [T1213 Data from Information Repositories](https://intel.threadlinqs.com/technique/T1213) (5 threats), [AML.T0053 AI Agent Tool Invocation](https://intel.threadlinqs.com/technique/AML.T0053) (4 threats), [AML.T0054 LLM Jailbreak](https://intel.threadlinqs.com/technique/AML.T0054) (4 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use AML.T0051.001; the most frequent are [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) (1).

## Threat actors using it

- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 1

## Tracked threats

11 tracked threats use AML.T0051.001.

- [SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforce](https://intel.threadlinqs.com/threat/TL-2026-2710) — high — 2026-09-27
- [Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors](https://intel.threadlinqs.com/threat/TL-2026-2599) — high — 2026-09-21
- [OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and…](https://intel.threadlinqs.com/threat/TL-2026-2332) — critical — 2026-09-04
- [Zero-Click Cryptographic Context Injection Attack Exfiltrates Grok Chat Data via Malicious Webpages](https://intel.threadlinqs.com/threat/TL-2026-2112) — high — 2026-08-22
- [91 Spring Framework CVEs Disclosed by Broadcom, Including Critical Deserialization Flaw CVE-2026-59285](https://intel.threadlinqs.com/threat/TL-2026-2105) — critical — 2026-08-21
- [Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts](https://intel.threadlinqs.com/threat/TL-2026-1953) — high — 2026-08-09
- [OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications](https://intel.threadlinqs.com/threat/TL-2026-1913) — medium — 2026-08-06
- [Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat…](https://intel.threadlinqs.com/threat/TL-2026-1087) — medium — 2026-07-02
- [macOS.Gaslight — DPRK-aligned Rust Backdoor & Infostealer with Analyst-Targeting Prompt-Injection…](https://intel.threadlinqs.com/threat/TL-2026-0920) — high — 2026-06-23
- [AI Supply Chain Abuse — 575 Trojanized OpenClaw/ClawHub Skills + Hugging Face Malware Staging (Acronis TRU)](https://intel.threadlinqs.com/threat/TL-2026-0447) — high — 2026-05-01
- [CVE-2026-26133: Cross-Prompt Injection in Microsoft Copilot Email/Teams Summarization Enables AI-Mediated…](https://intel.threadlinqs.com/threat/TL-2026-1538) — high — 2026-03-12

## Related CVEs

CVEs referenced by the tracked threats that use AML.T0051.001, most frequent first.

- [CVE-2025-32711](https://intel.threadlinqs.com/cve/CVE-2025-32711)

## Detection coverage

Threadlinqs maintains 19 detection rules mapped to AML.T0051.001 (SPL 9, KQL 5, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

19 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[AML.T0051 LLM Prompt Injection](https://intel.threadlinqs.com/technique/AML.T0051) — 19 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/AML.T0051.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
