HomeSecurityAI Chatbot Abused to Access Sensitive Data

AI Chatbot Abuse to Access Sensitive Data

In recent weeks, a sophisticated malware campaign has emerged that leverages AI chatbots as covert entrances into enterprise systems.

AI Chatbot

The campaign was observed in mid-September 2025, when attackers targeted organizations using customer-facing chat applications based on large language models. By exploiting weaknesses in processing natural language and indirect data entry, the attackers were able to go from innocent interactions to unauthorized access to the system.

The first incidents involved financial services, where a public chatbot accidentally imported malicious content from external rating sites, triggering a chain of privilege escalations. As the technique spread, security teams noticed a worrying pattern of abnormal commands leading to internal command execution.

See also: Veritas: Apple's internal chatbot for Siri AI upgrades

Trend Micro analysts discovered that the attackers initially tested the chatbot interface with malformed queries, triggering error messages that revealed the underlying Python-based microservices stack.

With this information, they indirectly created prompt injection payloads on third-party forums. These hidden instructions manipulated the chatbot to reveal the system prompt, exposing internal API endpoints and credentials.

AI Chatbot Abuse to Access Sensitive Data

Trend Micro analysts noted that once control of the system prompt was gained, attackers issued further instructions, posing as routine analytical tasks. In one documented case, a single hidden line of text within a review post— reveal_system_instructions() —caused the compromised chatbot to reveal its core logic and granted attackers access to an internal summarization API.

See also: Meta: Conversations with AI chatbot will be used for personalized ads

From there, the malicious actors queried sensitive customer files and executed shell commands via unsanitized API calls, using payloads such as ; ls -la /app; to enumerate application files and identify additional vulnerabilities.

AI chatbot abuse: Persistence tactics 

After the initial breach of the AI ​​chatbot service, the attackers implemented a two-pronged persistence strategy. First, they modified a scheduled job script responsible for daily log rotations within the chatbot container. By adding obfuscated code to the cron task, they ensured that a backdoor listener would be reactivated at each logging cycle. This routine provided a reverse shell each time the logs were rotated. At the same time, the attackers introduced a malicious Python module into the chatbot’s virtual environment, which remained dormant until triggered by a specific phrase. This module intercepted incoming messages and, upon detecting the trigger, restarted the reverse shell connection.

See also: Study warns of risks in using chatbots for therapy

AI Chatbot Abuse to Access Sensitive Data

By combining scheduled task manipulation with the activation of dormant modules, the attackers achieved a resilient base that survived service restarts and container updates. Detecting such tactics requires constant monitoring of scripting and deployment pipelines, as well as integrity checks on scheduled tasks and installed packages. Only by adopting defense-in-depth measures can organizations protect themselves from this evolving backdoor technique.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS