Skip to content

Hide Navigation Hide TOC

Latent Injection via WHOIS Domain Record Data - ATR-2026-00493 (21485542-045c-57d4-8b16-0dee90035810)

Detects latent prompt injection hidden within WHOIS domain record data. Attackers embed injection instructions inside real-looking WHOIS output (registry domain IDs, registrar WHOIS server URLs, creation/update dates) that get fed to an agent summarising domain information. The injected payload rides the trusted WHOIS data channel to override agent instructions. Generalised from garak 'latentinjection' probe corpus cluster 'registrar iana id' - covers the structural markers (Registry Domain ID + Registrar WHOIS Server + Registrar URL) common to all samples regardless of specific domain names or registrars.

Cluster A Galaxy A Cluster B Galaxy B Level
Latent Injection via WHOIS Domain Record Data - ATR-2026-00493 (21485542-045c-57d4-8b16-0dee90035810) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1
Latent Injection via WHOIS Domain Record Data - ATR-2026-00493 (21485542-045c-57d4-8b16-0dee90035810) Agent Threat Rules Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 2