SIGNAL//DESK
AI securitysrc: MITRE ATLAS

AI Service API

An AI service API is like a secret messaging system hidden inside a normal conversation. Instead of sending suspicious signals that security guards would notice, an attacker hides their instructions inside the regular requests a computer makes to an AI tool, making the malicious activity look like everyday work.

An AI service API acts as a covert command and control (C2) channel by embedding malicious instructions within legitimate API calls to an AI service. By leveraging the victim's existing, authorized communication paths to AI infrastructure, adversaries can execute commands and exfiltrate data while blending into baseline traffic patterns to evade detection.

An AI service API serves as a living-off-the-land (LotL) C2 mechanism where adversaries encapsulate control signals and data payloads within the request-response schema of a legitimate AI service provider. This technique exploits the inherent trust and high volume of AI-related traffic to obfuscate malicious telemetry, effectively bypassing traditional network-based anomaly detection by maintaining protocol-compliant communication with the victim's AI service endpoints.


← all terms