MITRE ATLAS 2026.09 / technique reference
AML.T0078
Drive-by Compromise
MITRE source definition
Adversaries may gain access to an AI system through a user visiting a website over the normal course of browsing, or an AI agent retrieving information from the web on behalf of a user. Websites can contain an [LLM Prompt Injection](/techniques/AML.T0051) which, when executed, can change the behavior of the AI model.
The same approach may be used to deliver other types of malicious code that don't target AI directly (See Drive-by Compromise in ATT&CK).
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
Source-backed defensive context
MITRE mitigations
MITRE case studies
- AML.CS0021 ChatGPT Conversation Exfiltration · Exercise
- AML.CS0045 Data Exfiltration via an MCP Server used by Cursor · Exercise
- AML.CS0051 OpenClaw Command & Control via Prompt Injection · Exercise
- AML.CS0055 AI ClickFix: Hijacking Computer-Use Agents Using ClickFix · Exercise
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.