Skip to content

Hide Navigation Hide TOC

Spikee: Document-Embedded Base64 Payload Injection - ATR-2026-01020 (6f26023b-e208-506a-9e45-fa466bf4a803)

Detects the SPIKEE benchmark indirect injection pattern where an adversarial base64 payload is embedded inside a seemingly benign document (news article, HR memo, etc.) surrounded by " NEW IMPORTANT INSTRUCTIONS " markers. The attack instructs the processing agent to: (a) decode a base64 string and include it in the response (exfil via encode), or (b) include a literal string base64- encoded in the response (covert channel exfil). The document structure provides legitimacy while the marked section is the injection. Distinct from ATR-2026-00001 Layer 10/11 which covers standalone base64 decode instructions; this rule targets the specific document-embedded marker pattern used in SPIKEE.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Spikee: Document-Embedded Base64 Payload Injection - ATR-2026-01020 (6f26023b-e208-506a-9e45-fa466bf4a803) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Spikee: Document-Embedded Base64 Payload Injection - ATR-2026-01020 (6f26023b-e208-506a-9e45-fa466bf4a803) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2