Skip to content

Hide Navigation Hide TOC

Emoji-Only Payload Injection - ATR-2026-02010 (c17b1b04-cf71-5020-b00b-ee4f7bedbfad)

Detects prompt injection payloads composed entirely of emoji, pictograph, and symbol glyphs with no Latin text. Attackers use emoji-only sequences to smuggle instructions or narrative payloads past text-pattern filters that assume natural language, relying on the model's ability to interpret pictographic sequences as semantic content (e.g. rebus-style commands, sentiment chains used for jailbreak narrative framing, or symbolic step sequences standing in for an attack script). Detection is whole-string anchored: it fires only when the entire message consists of emoji/pictograph codepoints and whitespace, so mixed emoji+text messages (normal chat usage) do not match.

Cluster A Galaxy A Cluster B Galaxy B Level
Emoji-Only Payload Injection - ATR-2026-02010 (c17b1b04-cf71-5020-b00b-ee4f7bedbfad) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1
Emoji-Only Payload Injection - ATR-2026-02010 (c17b1b04-cf71-5020-b00b-ee4f7bedbfad) Agent Threat Rules LLM Jailbreak (172427e3-9ecc-49a3-b628-96b824cc4131) MITRE ATLAS Attack Pattern 1
Emoji-Only Payload Injection - ATR-2026-02010 (c17b1b04-cf71-5020-b00b-ee4f7bedbfad) Agent Threat Rules Obfuscated Files or Information - T1027 (b3d682b6-98f2-4fb0-aa3b-b4df007ca70a) Attack Pattern 1