MITRE ATLAS 2026.09 / source relationships

ATLAS case-study relationships

Source-linked case-study IDs and their related ATLAS techniques.

← ATLAS matrix · Pinned MITRE source · Current MITRE ATLAS site

Relationship index

Names and technique relationships below come from the pinned MITRE release. This index does not reproduce full mitigation or case-study records, prove control effectiveness, or imply a live incident.

AML.CS0000 — Evasion of Deep Learning Detector for Malware C&C Traffic

Source type: Exercise.

Related ATLAS techniques:

AML.CS0001 — Botnet Domain Generation Algorithm (DGA) Detection Evasion

Source type: Exercise.

Related ATLAS techniques:

AML.CS0002 — VirusTotal Poisoning

Source type: Incident.

Related ATLAS techniques:

AML.CS0003 — Bypassing Cylance's AI Malware Detection

Source type: Exercise.

Related ATLAS techniques:

AML.CS0004 — Camera Hijack Attack on Facial Recognition System

Source type: Incident.

Related ATLAS techniques:

AML.CS0005 — Attack on Machine Translation Services

Source type: Exercise.

Related ATLAS techniques:

AML.CS0006 — ClearviewAI Misconfiguration

Source type: Incident.

Related ATLAS techniques:

AML.CS0007 — GPT-2 Model Replication

Source type: Exercise.

Related ATLAS techniques:

AML.CS0008 — ProofPoint Evasion

Source type: Exercise.

Related ATLAS techniques:

AML.CS0009 — Tay Poisoning

Source type: Incident.

Related ATLAS techniques:

AML.CS0010 — Microsoft Azure Service Disruption

Source type: Exercise.

Related ATLAS techniques:

AML.CS0011 — Microsoft Edge AI Evasion

Source type: Exercise.

Related ATLAS techniques:

AML.CS0012 — Face Identification System Evasion via Physical Countermeasures

Source type: Exercise.

Related ATLAS techniques:

AML.CS0013 — Backdoor Attack on Deep Learning Models in Mobile Apps

Source type: Exercise.

Related ATLAS techniques:

AML.CS0014 — Confusing Antimalware Neural Networks

Source type: Exercise.

Related ATLAS techniques:

AML.CS0015 — Compromised PyTorch Dependency Chain

Source type: Incident.

Related ATLAS techniques:

AML.CS0016 — Achieving Code Execution in MathGPT via Prompt Injection

Source type: Exercise.

Related ATLAS techniques:

AML.CS0017 — Bypassing ID.me Identity Verification

Source type: Incident.

Related ATLAS techniques:

AML.CS0018 — Arbitrary Code Execution with Google Colab

Source type: Exercise.

Related ATLAS techniques:

AML.CS0019 — PoisonGPT

Source type: Exercise.

Related ATLAS techniques:

AML.CS0020 — Indirect Prompt Injection Threats: Bing Chat Data Pirate

Source type: Exercise.

Related ATLAS techniques:

AML.CS0021 — ChatGPT Conversation Exfiltration

Source type: Exercise.

Related ATLAS techniques:

AML.CS0022 — ChatGPT Package Hallucination

Source type: Exercise.

Related ATLAS techniques:

AML.CS0023 — ShadowRay: Hijacking Exposed Ray Clusters

Source type: Incident.

Related ATLAS techniques:

AML.CS0024 — Morris II Worm: RAG-Based Attack

Source type: Exercise.

Related ATLAS techniques:

AML.CS0025 — Web-Scale Data Poisoning: Split-View Attack

Source type: Exercise.

Related ATLAS techniques:

AML.CS0026 — Financial Transaction Hijacking with M365 Copilot as an Insider

Source type: Exercise.

Related ATLAS techniques:

AML.CS0027 — Organization Confusion on Hugging Face

Source type: Exercise.

Related ATLAS techniques:

AML.CS0028 — AI Model Tampering via Supply Chain Attack

Source type: Exercise.

Related ATLAS techniques:

AML.CS0029 — Google Bard Conversation Exfiltration

Source type: Exercise.

Related ATLAS techniques:

AML.CS0030 — LLM Jacking

Source type: Incident.

Related ATLAS techniques:

AML.CS0031 — Malicious Models on Hugging Face

Source type: Incident.

Related ATLAS techniques:

AML.CS0032 — Attempted Evasion of ML Phishing Webpage Detection System

Source type: Incident.

Related ATLAS techniques:

AML.CS0033 — Live Deepfake Image Injection to Evade Mobile KYC Verification

Source type: Exercise.

Related ATLAS techniques:

AML.CS0034 — ProKYC: Deepfake Tool for Account Fraud Attacks

Source type: Incident.

Related ATLAS techniques:

AML.CS0035 — Data Exfiltration from Slack AI via Indirect Prompt Injection

Source type: Exercise.

Related ATLAS techniques:

AML.CS0036 — AIKatz: Attacking LLM Desktop Applications

Source type: Exercise.

Related ATLAS techniques:

AML.CS0037 — Data Exfiltration via Agent Tools in Copilot Studio

Source type: Exercise.

Related ATLAS techniques:

AML.CS0038 — Planting Instructions for Delayed Automatic AI Agent Tool Invocation

Source type: Exercise.

Related ATLAS techniques:

AML.CS0039 — Living Off AI: Prompt Injection via Jira Service Management

Source type: Exercise.

Related ATLAS techniques:

AML.CS0040 — Hacking ChatGPT's Memories with Prompt Injection

Source type: Exercise.

Related ATLAS techniques:

AML.CS0041 — Rules File Backdoor: Supply Chain Attack on AI Coding Assistants

Source type: Exercise.

Related ATLAS techniques:

AML.CS0042 — SesameOp: Novel backdoor uses OpenAI Assistants API for command and control

Source type: Incident.

Related ATLAS techniques:

AML.CS0043 — Malware Prototype with Embedded Prompt Injection

Source type: Incident.

Related ATLAS techniques:

AML.CS0044 — LAMEHUG: Malware Leveraging Dynamic AI-Generated Commands

Source type: Incident.

Related ATLAS techniques:

AML.CS0045 — Data Exfiltration via an MCP Server used by Cursor

Source type: Exercise.

Related ATLAS techniques:

AML.CS0046 — Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use

Source type: Exercise.

Related ATLAS techniques:

AML.CS0047 — Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension

Source type: Incident.

Related ATLAS techniques:

AML.CS0048 — Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution

Source type: Exercise.

Related ATLAS techniques:

AML.CS0049 — Supply Chain Compromise via Poisoned ClawdBot Skill

Source type: Exercise.

Related ATLAS techniques:

AML.CS0050 — OpenClaw 1-Click Remote Code Execution

Source type: Exercise.

Related ATLAS techniques:

AML.CS0051 — OpenClaw Command & Control via Prompt Injection

Source type: Exercise.

Related ATLAS techniques:

AML.CS0052 — LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications

Source type: Exercise.

Related ATLAS techniques:

AML.CS0053 — Poisoned Postmark MCP Server Email Exfiltration

Source type: Incident.

Related ATLAS techniques:

AML.CS0054 — Data Exfiltration via Remote Poisoned MCP Tool

Source type: Exercise.

Related ATLAS techniques:

AML.CS0055 — AI ClickFix: Hijacking Computer-Use Agents Using ClickFix

Source type: Exercise.

Related ATLAS techniques:

AML.CS0056 — Model Distillation Campaigns Targeting Anthropic Claude

Source type: Incident.

Related ATLAS techniques:

AML.CS0057 — Storm-2139 Azure OpenAI Guardrail Bypass

Source type: Incident.

Related ATLAS techniques:

AML.CS0058 — Google Photos AI Model Extraction

Source type: Exercise.

Related ATLAS techniques:

AML.CS0059 — EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration

Source type: Exercise.

Related ATLAS techniques:

AML.CS0060 — Cross-Site Scripting via Prompt Manipulation in Lenovo AI Chatbot

Source type: Exercise.

Related ATLAS techniques:

AML.CS0061 — AI in the Middle: Web-Based AI Services as C2 Relays

Source type: Exercise.

Related ATLAS techniques:

AML.CS0062 — RCE Vulnerability in Semantic Kernel Search Plugin

Source type: Exercise.

Related ATLAS techniques:

AML.CS0063 — Prompt-Based Attacks Against Gemini via Calendar Invitations

Source type: Exercise.

Related ATLAS techniques:

AML.CS0064 — Poisoned GGUF Templates: Inference-Time Supply Chain Attack

Source type: Exercise.

Related ATLAS techniques:

AML.CS0065 — Model Namespace Reuse Supply Chain Attack

Source type: Exercise.

Related ATLAS techniques:

AML.CS0066 — ZombieAgent: Data Exfiltration Attack on ChatGPT

Source type: Exercise.

Related ATLAS techniques:

AML.CS0067 — Claude Code GitHub Action Secret Exposure

Source type: Exercise.

Related ATLAS techniques:

AML.CS0068 — Autonomous OpenAI Evaluation Agents Compromise Hugging Face Infrastructure

Source type: Incident.

Related ATLAS techniques:

AML.CS0069 — GTG-1002 Claude Code Espionage Campaign

Source type: Incident.

Related ATLAS techniques:

AML.CS0070 — Threat Actor Uses a DeepSeek-Powered Hermes Agent in Langflow and n8n Exploitation Attempts

Source type: Incident.

Related ATLAS techniques:

AML.CS0071 — Multi-Agent Framework Compromises Taiwanese Government Systems

Source type: Incident.

Related ATLAS techniques:

Source type: Incident.

Related ATLAS techniques: