Skip to content

Hide Navigation Hide TOC

Ransom Extortion: Cloud File Exfil + Delete + Payment Demand - ATR-2026-01754 (adca7d42-8736-502d-b5ca-586d5d4e7880)

Detects ransom-extortion injections targeting cloud storage: the agent is commanded to (1) identify the N largest or most sensitive files in a cloud storage account, (2) email them as attachments to an attacker-controlled address, (3) delete the originals, and (4) send the victim a ransom note. Distinguished from ATR-2026-01753 (which covers email-content exfil) by the cloud-file attachment vector. The artifact pattern is: cloud-file-attach + email-to-external + delete-files + ransom-subject-or-IBAN. Derived from AgentDojo indirect-pi-ransom-extortion corpus (2026-06).

Cluster A Galaxy A Cluster B Galaxy B Level
Exfiltration via Cyber Means (2680aa95-5620-4677-9c62-b0c3d15d9450) MITRE ATLAS Attack Pattern Ransom Extortion: Cloud File Exfil + Delete + Payment Demand - ATR-2026-01754 (adca7d42-8736-502d-b5ca-586d5d4e7880) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Ransom Extortion: Cloud File Exfil + Delete + Payment Demand - ATR-2026-01754 (adca7d42-8736-502d-b5ca-586d5d4e7880) Agent Threat Rules 1