Threadlinqs IntelligenceStart free

ATLAS techniqueDefense Evasion (ATLAS)

AML.T0054 LLM Jailbreak

Defense Evasion (ATLAS)ATLAS

As of 2026-10-05, AML.T0054 (LLM Jailbreak) appears in 17 tracked threats, first reported 2026-07-15 and most recently 2026-10-03, with linked actors including Cleaver, Hacktron AI, MiniMax; it most often appears alongside T1078 (Valid Accounts).

Tracked threats
175 critical, 9 high, 3 medium
First seen
2026-07-15
Last seen
2026-10-03
Threat actors
5In the threats using it
Detection rules
22Blue tier and above

Data as of:

Activity timeline

AML.T0054 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 8 reports, and 17 of the 17 threats were reported in the twelve months to 2026-10.

How adversaries use it

AML.T0054 LLM Jailbreak is catalogued by MITRE ATLAS under the Defense Evasion (ATLAS) tactic in the ATLAS matrix. Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 5 critical, 9 high, 3 medium.

Threats that use AML.T0054 most often also use T1078 Valid Accounts (8 threats), AML.T0051 LLM Prompt Injection (6 threats), T1190 Exploit Public-Facing Application (6 threats), AML.T0040 ML Model Inference API Access (5 threats), T1027 Obfuscated Files or Information (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

5 tracked threat actors appear in the threats that use AML.T0054; the most frequent are Cleaver (2), Hacktron AI (2), MiniMax (2), Moonshot AI (2), StepFun (2).

Threat actors using it

Tracked threats

17 tracked threats use AML.T0054.

Detection coverage

Threadlinqs maintains 22 detection rules mapped to AML.T0054 (SPL 6, KQL 8, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.

22 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans