Skip to content
Search
paperJuly 2026Unreviewed

Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting

Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, Ben Nassi

Abstract

The growing adoption of agentic LLM applications has introduced a new threat previously named as promptware. While prior work has established that adversaries can exploit direct channels to LLM applications to apply promptware under weak threat models, many applications do not provide any direct channels that could be exploited for prompt injection beyond the Internet. This raises a question: can attackers exploit LLM applications at scale without any direct channels in practical threat models?

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{spira2026beware,
  title = {{Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting}},
  author = {Aya Spira and Stav Cohen and Elad Feldman and Ron Bitton and Avishai Wool and Ben Nassi},
  year = {2026},
  month = jul,
  eprint = {2607.07433},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2607.07433}
}