# AML.T0051 LLM Prompt Injection

> As of 2026-10-05, AML.T0051 (LLM Prompt Injection) appears in 19 tracked threats, first reported 2026-07-02 and most recently 2026-10-04, with linked actors including Cleaver, MiniMax, Moonshot AI; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 19 (5 critical, 7 high, 7 medium)
- **First seen:** 2026-07-02
- **Last seen:** 2026-10-04
- **Threat actors:** 4
- **Detection rules:** 50 (counts only; Blue tier and above)

## Key facts

- **ID:** AML.T0051
- **Framework:** MITRE ATLAS
- **Tactics:** Execution (ATLAS)
- **Matrix:** ATLAS
- **Data as of:** 2026-10-05

## Activity timeline

AML.T0051 first appeared in tracked threats on 2026-07-02 and was most recently reported on 2026-10-04. The busiest month was 2026-08 with 8 reports, and 19 of the 19 threats were reported in the twelve months to 2026-10.

## How adversaries use it

AML.T0051 LLM Prompt Injection is catalogued by MITRE ATLAS under the Execution (ATLAS) tactic in the ATLAS matrix. Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 5 critical, 7 high, 7 medium.

Threats that use AML.T0051 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (10 threats), [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (9 threats), [T1204 User Execution](https://intel.threadlinqs.com/technique/T1204) (7 threats), [AML.T0054 LLM Jailbreak](https://intel.threadlinqs.com/technique/AML.T0054) (6 threats), [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use AML.T0051; the most frequent are [Cleaver](https://intel.threadlinqs.com/actor/Cleaver) (2), [MiniMax](https://intel.threadlinqs.com/actor/MiniMax) (2), [Moonshot AI](https://intel.threadlinqs.com/actor/Moonshot%20AI) (2), [StepFun](https://intel.threadlinqs.com/actor/StepFun) (2).

## Threat actors using it

- [Cleaver](https://intel.threadlinqs.com/actor/Cleaver) — 2
- [MiniMax](https://intel.threadlinqs.com/actor/MiniMax) — 2
- [Moonshot AI](https://intel.threadlinqs.com/actor/Moonshot%20AI) — 2
- [StepFun](https://intel.threadlinqs.com/actor/StepFun) — 2

## Tracked threats

19 tracked threats use AML.T0051.

- [Coordinated model-distillation campaign against OpenAI: 15,000+ accounts attempt to extract protected model…](https://intel.threadlinqs.com/threat/TL-2026-2915) — medium — 2026-10-04
- [Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2707) — medium — 2026-09-27
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…](https://intel.threadlinqs.com/threat/TL-2026-2642) — high — 2026-09-24
- [Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…](https://intel.threadlinqs.com/threat/TL-2026-2631) — high — 2026-09-23
- [China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models](https://intel.threadlinqs.com/threat/TL-2026-2413) — critical — 2026-09-09
- [China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier…](https://intel.threadlinqs.com/threat/TL-2026-2405) — high — 2026-09-08
- [Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…](https://intel.threadlinqs.com/threat/TL-2026-2390) — high — 2026-09-08
- [Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-2299) — medium — 2026-09-02
- [Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271…](https://intel.threadlinqs.com/threat/TL-2026-2185) — critical — 2026-08-28
- [Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Enables Sandbox Escape and RCE on Host](https://intel.threadlinqs.com/threat/TL-2026-2121) — critical — 2026-08-23
- [Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…](https://intel.threadlinqs.com/threat/TL-2026-2065) — critical — 2026-08-19
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — high — 2026-08-18
- [CSS Bomb Attacks: CSS-Based Trust-Boundary Bypass Leaks Webmail Passwords and Tokens (Outlook, Gmail, Yahoo…](https://intel.threadlinqs.com/threat/TL-2026-1968) — high — 2026-08-10
- [CSS Bomb: JavaScript-Free CSS Keylogging and Token-Theft Attacks Against Gmail, Outlook, Yahoo Mail, AOL…](https://intel.threadlinqs.com/threat/TL-2026-1956) — high — 2026-08-09
- [RovoBlast: One-Click Parameter-to-Prompt Injection in Atlassian Rovo AI Exposes Confluence, Jira, and…](https://intel.threadlinqs.com/threat/TL-2026-1942) — critical — 2026-08-08
- [OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications](https://intel.threadlinqs.com/threat/TL-2026-1913) — medium — 2026-08-06
- [Text-Salting Phishing Campaigns Abuse CSS-Hidden Text to Evade AI Email Security Filters](https://intel.threadlinqs.com/threat/TL-2026-1426) — medium — 2026-07-16
- [Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat…](https://intel.threadlinqs.com/threat/TL-2026-1087) — medium — 2026-07-02

## Related CVEs

CVEs referenced by the tracked threats that use AML.T0051, most frequent first.

- [CVE-2025-32711](https://intel.threadlinqs.com/cve/CVE-2025-32711)
- [CVE-2026-24301](https://intel.threadlinqs.com/cve/CVE-2026-24301)
- [CVE-2026-42271](https://intel.threadlinqs.com/cve/CVE-2026-42271)
- [CVE-2026-48710](https://intel.threadlinqs.com/cve/CVE-2026-48710)

## Detection coverage

Threadlinqs maintains 50 detection rules mapped to AML.T0051 (SPL 17, KQL 15, Sigma 18). Rule content is available to Blue tier accounts and above; this page shows counts only.

50 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- AML.T0051.000 Direct — 1 tracked threat
- [AML.T0051.001 LLM Prompt Injection: Indirect](https://intel.threadlinqs.com/technique/AML.T0051.001) — 11 tracked threats
- AML.T0051.002 Triggered — 1 tracked threat

## Links

- Canonical page: https://intel.threadlinqs.com/technique/AML.T0051
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
