SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Machine Compromise

Machine compromise via AI means that hackers use the 'smart' features of a computer—like automated assistants or AI-driven tools—as a backdoor to take control of the device. Once they get in through these AI parts, they can do anything the computer can do, such as stealing your private files, logging your passwords, or hiding inside your system to spy on you long-term.

Machine compromise in an AI context occurs when an adversary exploits vulnerabilities in AI-enabled components, such as local agents or malicious AI artifacts, to gain unauthorized access. By manipulating these components, the attacker inherits the agent's system permissions, enabling them to execute arbitrary code, harvest credentials, exfiltrate sensitive data, and establish persistent access to the host environment.

Machine compromise via AI-enabled components refers to the exploitation of vulnerabilities within local AI agents or the injection of malicious payloads into AI artifacts to achieve unauthorized system-level execution. By subverting the integrity of these components, an adversary gains the effective privilege set of the AI process, facilitating arbitrary code execution, credential theft, data exfiltration, and the establishment of long-term persistence within the target infrastructure.


← all terms