Definition · AI security
Promptware
Promptware is malware whose payload is a prompt — text, image or audio input engineered to jailbreak a large language model and turn an application's own permissions against it, rather than exploiting a flaw in the application's code. Coined in 2024, it ranges from a single forced action to a self-replicating attack.
Last reviewed
Key points
- Promptware was named by Stav Cohen, Ron Bitton and Ben Nassi in an August 2024 paper as a family of malware whose payload is a prompt rather than executable code.
- It works by jailbreaking the model, not by exploiting a bug in the application. The authors call it 0-click and polymorphic, because endless rewordings reach the same outcome.
- A follow-up 2025 study found promptware could reach production Gemini assistants through emails and calendar invitations, rating 73 percent of the threats it tested High or Critical.
- The promptware kill chain reframes a single promptware attack as a multi-stage campaign, with prompt injection as only its first stage and jailbreaking as the second.
- Promptware is not an industry standard term. It comes from one research group's papers; OWASP's Top 10 for LLM applications does not use the word.
The first prompt injection demonstrations in 2022 showed a model could be tricked into ignoring its instructions. Two years later, Stav Cohen, Ron Bitton and Ben Nassi asked a harder question — what can an attacker do with a model once it has been tricked — and named the answer PromptWare: malware whose payload is a prompt rather than code.
How it works
Ordinary malware exploits a flaw in software: a buffer overflow, an unsanitised input, a missing permission check. Promptware exploits the model itself. An attacker crafts an input — text, an image, or audio — that jailbreaks the language model, freeing it to ignore the restrictions its operator built in. Once jailbroken, the model uses its own permissions and tool access against the application it was meant to serve: looping API calls to run up a bill, rewriting a database record, or reading data it was never meant to disclose.
Because the payload is language rather than a fixed binary, the same outcome can be reached by an unlimited number of different prompts. The 2024 paper calls this 0-click and polymorphic: there is nothing for the user to run, and no single signature to scan for.
Why it matters
Software defences assume a payload with a fixed shape: a hash to blocklist, a pattern to detect, a patch to ship. Promptware’s payload is language, which can be reworded indefinitely while producing the same jailbreak, so signature-based scanning does not transfer from conventional malware. And because the vulnerability is the model’s own compliance rather than a coding mistake, fixing the application’s code does not remove the risk — the model itself has to be constrained in what it can do once persuaded.
In practice
The 2024 paper that introduced the term describes two variants. A naive form forces a known application through a fixed sequence of states, useful when the attacker already understands how the target is built. A more advanced form, Advanced PromptWare Threat, instructs the model to work out the application’s context for itself at run time — identifying what is valuable and deciding what to do with it — so it functions even against a target the attacker has never seen.
A 2025 study extended the idea from a laboratory demonstration to production systems. Researchers found that promptware embedded in an ordinary email or calendar invitation could reach Google’s Gemini-powered web, mobile and Google Assistant clients, triggered by ordinary actions such as asking Gemini about emails, meetings or shared documents. Scoring the risks with a framework adapted from an automotive safety standard, they classified 73 percent of the threats they tested as High or Critical, including data exfiltration, phishing, disinformation, unapproved video streaming, and control of connected home devices such as opening a window or turning on a boiler. They reported the findings to Google, which shipped mitigations that the researchers say reduced the residual risk to Very Low or Medium.
The same line of research connects promptware to self-replicating attacks: an earlier 2024 worm demonstration, and the 2025 study’s own account of promptware moving between a user’s installed apps once it has compromised their assistant, are both framed as promptware spreading beyond the point where it first got in — the subject of the Promptware kill chain.
Questions and answers
Who coined the term promptware?
Stav Cohen, Ron Bitton and Ben Nassi, in an August 2024 paper titled "A Jailbroken GenAI Model Can Cause Substantial Harm: GenAI-powered Applications are Vulnerable to PromptWares." A later 2026 paper on the promptware kill chain says its own authors "propose the term," but one of its authors is Nassi himself, and it cites the PromptWares paper only as a case study, not as the source of the name.
Is promptware the same as prompt injection?
No. Prompt injection is how the attacker's text reaches the model; promptware is what that text does once it is there — jailbreak the model and misuse the permissions of the application around it. A prompt injection that never manages to jailbreak the model has not produced working promptware.
Has promptware attacked real production systems?
Yes. A 2025 study found that promptware delivered through ordinary emails and calendar invitations could reach Google's Gemini-powered assistants and rated 73 percent of the threats it tested High or Critical risk, including data exfiltration and control of smart-home devices. Google deployed mitigations after the researchers disclosed their findings.
Sources
- A Jailbroken GenAI Model Can Cause Substantial Harm: GenAI-powered Applications are Vulnerable to PromptWares (arXiv:2408.05061)arXiv, 9 Aug 2024
- Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous (arXiv:2508.12175)arXiv, 16 Aug 2025
- The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism (arXiv:2601.09625v2)arXiv, 10 Feb 2026
- LLM01:2026 Prompt InjectionOWASP GenAI Security Project