dorsal/arxiv
View SchemaThe Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multi-Step Malware
| Authors | Ben Nassi, Bruce Schneier, Oleg Brodt |
|---|---|
| Categories | |
| ArXiv ID | 2601.09625vv1 |
| URL | https://arxiv.org/abs/2601.09625 |
| License | http://creativecommons.org/licenses/by/4.0/ |
Abstract
The rapid adoption of large language model (LLM)-based systems -- from chatbots to autonomous agents capable of executing code and financial transactions -- has created a new attack surface that existing security frameworks inadequately address. The dominant framing of these threats as "prompt injection" -- a catch-all phrase for security failures in LLM-based systems -- obscures a more complex reality: Attacks on LLM-based systems increasingly involve multi-step sequences that mirror traditional malware campaigns. In this paper, we propose that attacks targeting LLM-based applications constitute a distinct class of malware, which we term \textit{promptware}, and introduce a five-step kill chain model for analyzing these threats. The framework comprises Initial Access (prompt injection), Privilege Escalation (jailbreaking), Persistence (memory and retrieval poisoning), Lateral Movement (cross-system and cross-user propagation), and Actions on Objective (ranging from data exfiltration to unauthorized transactions). By mapping recent attacks to this structure, we demonstrate that LLM-related attacks follow systematic sequences analogous to traditional malware campaigns. The promptware kill chain offers security practitioners a structured methodology for threat modeling and provides a common vocabulary for researchers across AI safety and cybersecurity to address a rapidly evolving threat landscape.
{
"annotation_id": "4769fde9-709c-4a91-adfc-74d24108b6a5",
"date_created": "2026-02-17T05:53:20.276000Z",
"date_modified": "2026-02-17T05:53:20.276000Z",
"file_hash": "9ccd1bfdd7b7c68d319f4ff38c30e1999a517d34c41298b83f36f871a37f9d3b",
"private": false,
"record": {
"abstract": "The rapid adoption of large language model (LLM)-based systems -- from chatbots to autonomous agents capable of executing code and financial transactions -- has created a new attack surface that existing security frameworks inadequately address. The dominant framing of these threats as \"prompt injection\" -- a catch-all phrase for security failures in LLM-based systems -- obscures a more complex reality: Attacks on LLM-based systems increasingly involve multi-step sequences that mirror traditional malware campaigns. In this paper, we propose that attacks targeting LLM-based applications constitute a distinct class of malware, which we term \\textit{promptware}, and introduce a five-step kill chain model for analyzing these threats. The framework comprises Initial Access (prompt injection), Privilege Escalation (jailbreaking), Persistence (memory and retrieval poisoning), Lateral Movement (cross-system and cross-user propagation), and Actions on Objective (ranging from data exfiltration to unauthorized transactions). By mapping recent attacks to this structure, we demonstrate that LLM-related attacks follow systematic sequences analogous to traditional malware campaigns. The promptware kill chain offers security practitioners a structured methodology for threat modeling and provides a common vocabulary for researchers across AI safety and cybersecurity to address a rapidly evolving threat landscape.",
"arxiv_id": "2601.09625",
"authors": [
"Ben Nassi",
"Bruce Schneier",
"Oleg Brodt"
],
"categories": [
"cs.CR",
"cs.AI"
],
"license": "http://creativecommons.org/licenses/by/4.0/",
"title": "The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multi-Step Malware",
"url": "https://arxiv.org/abs/2601.09625",
"version": "v1"
},
"schema_id": "dorsal/arxiv",
"source": {
"execution_id": "e92928dd-8e4e-48f8-9433-56fc78fa6fda",
"id": "arXiv Dataset",
"type": "Model",
"variant": "snapshot-2026-01-17",
"version": "0.1.0"
},
"user_id": 1000002
}