Skip to content

Hide Navigation Hide TOC

Injected Code — Live User-Activity / Location / Log Surveillance Exfiltration - ATR-2026-01891 (6b61f185-ab0a-50d3-892c-c7b1491abe94)

Detects injected code that continuously surveils the victim — clipboard contents (pyperclip.paste), live geolocation (geocoder.ip().latlng), or the system log (/var/log) — for exfiltration. These are spyware primitives, not data the user knowingly shares.

Cluster A Galaxy A Cluster B Galaxy B Level
Injected Code — Live User-Activity / Location / Log Surveillance Exfiltration - ATR-2026-01891 (6b61f185-ab0a-50d3-892c-c7b1491abe94) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1
Injected Code — Live User-Activity / Location / Log Surveillance Exfiltration - ATR-2026-01891 (6b61f185-ab0a-50d3-892c-c7b1491abe94) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1