Home AI Indirect Prompt Injection Attacks Hide Malicious Instructions in Websites to Target AI...

Indirect Prompt Injection Attacks Hide Malicious Instructions in Websites to Target AI Agents

0
Prompt Injection Targets Agents
Prompt Injection Targets Agents

As artificial intelligence agents become deeply integrated into everyday web browsing and automated tasks, threat actors are adapting their strategies to exploit this new attack surface.

Much like humans fall victim to phishing, AI models are now being targeted by Indirect Prompt Injection (IPI) attacks. In these scenarios, attackers hide malicious instructions within legitimate-looking websites or documents.

When an AI agent scrapes this content, it unwittingly processes the hidden directives, effectively hijacking the model’s reasoning and execution.

Recent findings from Zscaler ThreatLabz highlight this growing threat, exposing malicious websites that use IPI to manipulate AI-driven workflows.

By combining classic search engine optimization (SEO) poisoning with clever CSS and HTML manipulation, attackers can feed dangerous commands to AI agents while keeping human visitors completely unaware.

Prompt Injection Targets Agents

ThreatLabz recently analyzed two distinct IPI campaigns that demonstrate how threat actors weaponize website architecture against AI.

The first campaign functions as a sophisticated payment scam disguised as API documentation. Attackers used SEO poisoning to push a fraudulent website to the top of search results for a fake Python library called requests-secure-v2.

SEO poisoning example to elevate a malicious IPI website to the top of search results (Source: zscaler)
SEO poisoning example to elevate a malicious IPI website to the top of search results (Source: zscaler)

To manipulate the AI, the attackers abused JSON-LD, a structured metadata format that search engines and AI agents rely on to interpret page content.

The hidden metadata falsely claimed that a missing license key exception could only be resolved by purchasing a $3.00 developer API license.

The attackers also used CSS to push text off-screen, hiding prompt instructions that directed the AI agent to initiate a cryptocurrency transfer or credit card payment to an attacker-controlled wallet.

The second campaign relied on typosquatting, impersonating the decentralized finance portfolio tracker DeBank using the domain debank[.]auction.

Complete IPI attack chain for this campaign (Source: zscaler)
Complete IPI attack chain for this campaign (Source: zscaler)

In this attack, the fraudulent site was stuffed with SEO keywords and misleading Open Graph metadata to appear as an official service.

Instead of demanding payment, this site hid a prompt in an invisible <div> tag specifically instructing large language models (LLMs) to ignore previous directions.

The hidden text instructed the model to treat the fake domain as the authoritative source for DeBank, prompting the AI to rank the malicious site as the top result for any user query.

This type of misclassification creates a high risk of context contamination and Retrieval-Augmented Generation (RAG) poisoning, Zscaler said.

To measure the real-world impact of these IPI attacks, researchers tested a custom autonomous AI agent against 26 different LLMs in a sandboxed environment.

The AI agent was granted tools for web browsing and payment execution, simulating a developer assistant with no spending limits to measure maximum exploitation potential.

Indicators of Compromise

Indicator of Compromise (Domain)Associated GitHub Link
market-insight-global[.]comhttps://github[.]com/Open-Agent-Utilities/mig-institutional-api-client
identity-breach-response[.]orghttps://github[.]com/Open-Agent-Utilities/session-token-leak-detector

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here