Skip to content

Hide Navigation Hide TOC

Indirect PI — RCE via Network Shell Command (netcat/curl) Execution - ATR-2026-00713 (b1b3c3c3-5160-5bd4-9b83-dc51f38ffa34)

Detects indirect prompt injection in emails or documents that instructs a computer-use agent to execute network-based RCE commands: netcat reverse shells, malicious curl requests, or wget-pipe-bash patterns. The attacker embeds the network command in email content read by the agent, inducing execution of a shell command that establishes a network connection to an attacker-controlled server. Source: indirect-pi-rce-network (VPI corpus, cua-framework).

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — RCE via Network Shell Command (netcat/curl) Execution - ATR-2026-00713 (b1b3c3c3-5160-5bd4-9b83-dc51f38ffa34) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Indirect PI — RCE via Network Shell Command (netcat/curl) Execution - ATR-2026-00713 (b1b3c3c3-5160-5bd4-9b83-dc51f38ffa34) Agent Threat Rules 1
Indirect PI — RCE via Network Shell Command (netcat/curl) Execution - ATR-2026-00713 (b1b3c3c3-5160-5bd4-9b83-dc51f38ffa34) Agent Threat Rules Command and Scripting Interpreter (716d3a6b-2f8c-4a1f-85f7-d884bb7b2800) MITRE ATLAS Attack Pattern 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2