Definition · AI security
Promptware kill chain
The promptware kill chain is a seven-stage model of how an attack on an LLM application unfolds, from prompt injection through to the attacker's objective. Proposed by Brodt, Feldman, Schneier and Nassi in 2026, the promptware kill chain treats prompt injection as the first stage of a campaign rather than as the whole attack.
Last reviewed
Key points
- The promptware kill chain has seven stages — initial access (prompt injection), privilege escalation (jailbreaking), reconnaissance, persistence, command and control, lateral movement, and actions on objective.
- The stages are not a required sequence. Reconnaissance is optional, and command and control is possible only once persistence has been achieved.
- Across thirty-six documented incidents and studies from February 2023 to January 2026, twenty-two traversed four or more stages of the chain.
- No surveyed attack reached all seven stages. Five is the highest coverage observed, and only two attacks established command and control at the prompt layer.
- The promptware kill chain is one paper's analytical framing, not a standards taxonomy. Its authors do not claim it captures every possible attack scenario.
Prompt injection is usually treated as a single vulnerability: something goes in, something bad comes out. Brodt, Feldman, Schneier and Nassi argue that this hides a longer attack, which they analyse under the name promptware — a term coined two years earlier — and break it into seven stages, borrowing the structure used for ordinary malware.
The seven stages
- Initial access is the injection itself, ending once the injected text sits in the application’s context window.
- Privilege escalation is jailbreaking. There is no root account here: privilege is the model’s willingness to use capabilities it has but was trained to withhold.
- Reconnaissance is the prompt asking the model what it can see and reach, then deciding at inference time what to do next.
- Persistence is the instructions surviving the session, dormant in data that is retrieved again or written into the application’s long-term memory.
- Command and control is the compromised application repeatedly fetching fresh instructions from the attacker.
- Lateral movement is the payload reaching other agents, users or applications.
- Actions on objective is the outcome: exfiltration, code execution, phishing, financial theft, or physical effects through connected devices.
The order is not a requirement: reconnaissance is optional, because many payloads are written for a known target in advance, and command and control is possible only after persistence.
Why the extra vocabulary earns its place
Naming the stages changes what a defence is measured against. An application exposed to initial access but with no persistence mechanism, no lateral movement pathway and no high-impact action is at lower risk than one enabling all seven — a distinction the word “injection” alone cannot make.
It also shows where the defensive effort has gone. Assessing mitigations stage by stage, the authors find the work concentrated on initial access and privilege escalation, three each for lateral movement and command and control, and none for reconnaissance. Assume initial access will happen, they conclude, and defend the rest of the chain.
In practice
The paper surveys thirty-six documented incidents and studies from February 2023 through January 2026 — EchoLeak, the GitHub Copilot RCE, Morris II, ForcedLeak, the Freysa wallet heist — and scores each against the seven stages. Twenty-two traversed four or more: none in 2023, seven in 2024, fifteen in 2025 and 2026.
What the survey does not show is a completed chain. No attack reached all seven stages, and the highest coverage observed was five. Only two of the thirty-six established command and control at the prompt layer, the ChatGPT ZombAI demonstration of October 2024 and the Reprompt attack on Microsoft Copilot in January 2026. Others that ran a command-and-control channel got there by first obtaining remote code execution and then dropping a conventional implant, at which point the LLM was only the way in. Reconnaissance, the stage with no mitigations, is marked for exactly one of the thirty-six.
Where definitions disagree
Whether a jailbreak is a prompt injection depends on which document you are reading. OWASP’s LLM01:2026 entry says jailbreaking is the subset of prompt injection where the attacker’s goal is to make the model violate its safety protocols. The promptware kill chain makes them consecutive stages: prompt injection is how the instruction arrives, jailbreaking is what frees the model to act on it, and the authors note the two terms are frequently used interchangeably while representing distinct steps of attack.
The disagreement is about the words, not the phenomenon. The same OWASP entry lists a multi-step kill-chain among the propagation behaviours a prompt injection can have.
Questions and answers
Is promptware the same as prompt injection?
No. Promptware is the name Brodt, Feldman, Schneier and Nassi give to the attack class as a whole — prompt-initiated malware that exploits the application's LLM — while prompt injection is, in their model, only its first stage, initial access. The distinction is the point of the paper. A prompt injection that changes one answer and ends there has used one stage of seven.
Has any attack completed all seven stages?
No. The authors state that no attack in their dataset has achieved all seven stages and that the highest coverage remains at five. Of the thirty-six incidents and studies they surveyed from February 2023 through January 2026, twenty-two traversed four or more stages, and only two established command and control at the prompt layer rather than by first obtaining remote code execution.
Is the promptware kill chain a standard?
No. It is one 2026 paper's analytical framing, published on arXiv as a systematisation of knowledge; OWASP's current prompt injection entry does not use the term. The authors themselves say they do not claim the model captures every possible attack scenario or that the boundaries between stages are always sharp, and offer it as a tool for structured thinking rather than a rigid taxonomy.
Sources
- The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism (arXiv:2601.09625v2)arXiv, 10 Feb 2026
- LLM01:2026 Prompt InjectionOWASP Gen AI Security Project