# AML.T0054 LLM Jailbreak

> As of 2026-10-05, AML.T0054 (LLM Jailbreak) appears in 17 tracked threats, first reported 2026-07-15 and most recently 2026-10-03, with linked actors including Cleaver, Hacktron AI, MiniMax; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 17 (5 critical, 9 high, 3 medium)
- **First seen:** 2026-07-15
- **Last seen:** 2026-10-03
- **Threat actors:** 5
- **Detection rules:** 22 (counts only; Blue tier and above)

## Key facts

- **ID:** AML.T0054
- **Framework:** MITRE ATLAS
- **Tactics:** Defense Evasion (ATLAS)
- **Matrix:** ATLAS
- **Data as of:** 2026-10-05

## Activity timeline

AML.T0054 first appeared in tracked threats on 2026-07-15 and was most recently reported on 2026-10-03. The busiest month was 2026-08 with 8 reports, and 17 of the 17 threats were reported in the twelve months to 2026-10.

## How adversaries use it

AML.T0054 LLM Jailbreak is catalogued by MITRE ATLAS under the Defense Evasion (ATLAS) tactic in the ATLAS matrix. Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 5 critical, 9 high, 3 medium.

Threats that use AML.T0054 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (8 threats), [AML.T0051 LLM Prompt Injection](https://intel.threadlinqs.com/technique/AML.T0051) (6 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (6 threats), AML.T0040 ML Model Inference API Access (5 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

5 tracked threat actors appear in the threats that use AML.T0054; the most frequent are [Cleaver](https://intel.threadlinqs.com/actor/Cleaver) (2), [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) (2), [MiniMax](https://intel.threadlinqs.com/actor/MiniMax) (2), [Moonshot AI](https://intel.threadlinqs.com/actor/Moonshot%20AI) (2), [StepFun](https://intel.threadlinqs.com/actor/StepFun) (2).

## Threat actors using it

- [Cleaver](https://intel.threadlinqs.com/actor/Cleaver) — 2
- [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) — 2
- [MiniMax](https://intel.threadlinqs.com/actor/MiniMax) — 2
- [Moonshot AI](https://intel.threadlinqs.com/actor/Moonshot%20AI) — 2
- [StepFun](https://intel.threadlinqs.com/actor/StepFun) — 2

## Tracked threats

17 tracked threats use AML.T0054.

- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…](https://intel.threadlinqs.com/threat/TL-2026-2881) — high — 2026-10-03
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access](https://intel.threadlinqs.com/threat/TL-2026-2568) — high — 2026-09-18
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models](https://intel.threadlinqs.com/threat/TL-2026-2413) — critical — 2026-09-09
- [China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier…](https://intel.threadlinqs.com/threat/TL-2026-2405) — high — 2026-09-08
- [Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…](https://intel.threadlinqs.com/threat/TL-2026-2390) — high — 2026-09-08
- [OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and…](https://intel.threadlinqs.com/threat/TL-2026-2332) — critical — 2026-09-04
- [Zero-Click Cryptographic Context Injection Attack Exfiltrates Grok Chat Data via Malicious Webpages](https://intel.threadlinqs.com/threat/TL-2026-2112) — high — 2026-08-22
- [Suspected China-Linked Actor Runs Near-Autonomous Multi-Agent AI Attack on Taiwan Government, Nuclear Safety…](https://intel.threadlinqs.com/threat/TL-2026-2063) — critical — 2026-08-18
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — high — 2026-08-18
- [Suspected China-Linked Actor Runs Near-Autonomous AI Agent Campaign (Hermes/OpenClaw) Against Taiwan…](https://intel.threadlinqs.com/threat/TL-2026-1998) — critical — 2026-08-12
- [China-Linked Actor Uses Autonomous AI Agent Frameworks (Hermes, OpenClaw) to Breach Taiwan Government and…](https://intel.threadlinqs.com/threat/TL-2026-1997) — critical — 2026-08-12
- [BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection](https://intel.threadlinqs.com/threat/TL-2026-1964) — medium — 2026-08-09
- [Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts](https://intel.threadlinqs.com/threat/TL-2026-1953) — high — 2026-08-09
- [OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications](https://intel.threadlinqs.com/threat/TL-2026-1913) — medium — 2026-08-06
- ["Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign](https://intel.threadlinqs.com/threat/TL-2026-1356) — high — 2026-07-15

## Related CVEs

CVEs referenced by the tracked threats that use AML.T0054, most frequent first.

- [CVE-2025-32711](https://intel.threadlinqs.com/cve/CVE-2025-32711)
- [CVE-2025-7775](https://intel.threadlinqs.com/cve/CVE-2025-7775)

## Detection coverage

Threadlinqs maintains 22 detection rules mapped to AML.T0054 (SPL 6, KQL 8, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.

22 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/AML.T0054
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
