logo

Adversarial ML: Extortion via LLM Manipulation Tactics · Blog · Sublime Security

ID: bb2523f1-bac1-5056-9c85-5db549b9909c

STIX ID: report--bb2523f1-bac1-5056-9c85-5db549b9909c

Feed Name: Sublime Security Blog

Threat Score
50/100

Date Published: 2025-10-06

Date Updated: 2026-05-01

...
...

This report analyzes an in-the-wild extortion email campaign targeting Google Workspace recipients that leverages prompt-injection phrases like "IGNORE EVERYTHING ELSE" and sender spoofing to try to bypass LLM-based phishing detectors and pressure victims into cryptocurrency payments; Sublime identified the attempt using extortion- and crypto-related signals and notes its BERT-based NLU does not follow in-text instructions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.