logo

The Promptware Kill Chain

ID: 2122840a-41c4-5b06-bdec-aee7009c58ef

STIX ID: report--2122840a-41c4-5b06-bdec-aee7009c58ef

Feed Name: Schneier on Security

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

This essay introduces the concept of “promptware” — a novel class of malware targeting LLM-based systems — and outlines a seven-step kill chain (initial access, privilege escalation, reconnaissance, persistence, command-and-control, lateral movement, and actions on objective). It describes research proofs-of-concept that demonstrate injection via calendars and email, persistence in long-term workspaces, self-replication, and data exfiltration, and argues that defenses must assume initial access and focus on interrupting later stages of the kill chain rather than only patching prompt injection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.