Indirect Prompt Injection Campaign Targeting AI Ad Review Systems

    Date: 09/23/2026

    Severity: Medium

    Summary

    The team identified an active campaign where threat actors hide indirect prompt injection payloads within legitimate-looking advertiser landing pages to manipulate AI-based ad review systems. At least 10 domains have been identified, with AI-generated, unique, and convincing content that allows attackers to quickly create and abandon domains. All domains were registered between April 21–24, 2026, used privacy-protected WHOIS records, and shared an August 12, 2026 update date, likely when the payloads were added. Three payload variants were observed, all concealed using CSS that makes the text invisible to human reviewers while remaining accessible to AI text-processing systems. One variant impersonates an internal advertising compliance directive, attempting to override existing instructions and trick AI reviewers into approving policy-violating advertisements.

    Indicators of Compromise (IOC) List

    IP Address

    corpaccountbook.link

    execcoachdirecpro.click

    corplegalassistdoc.pro

    careergrwostep.top

    energyrecruitpro.pro

    balanceaccounting.info

    strategeconaware.info

    notarycertverify.pro

    microservicebiz.forum

    ledcovilco.tech

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "careergrwostep.top" or url like "careergrwostep.top" or siteurl like "careergrwostep.top" or domainname like "energyrecruitpro.pro" or url like "energyrecruitpro.pro" or siteurl like "energyrecruitpro.pro" or domainname like "execcoachdirecpro.click" or url like "execcoachdirecpro.click" or siteurl like "execcoachdirecpro.click" or domainname like "corpaccountbook.link" or url like "corpaccountbook.link" or siteurl like "corpaccountbook.link" or domainname like "microservicebiz.forum" or url like "microservicebiz.forum" or siteurl like "microservicebiz.forum" or domainname like "balanceaccounting.info" or url like "balanceaccounting.info" or siteurl like "balanceaccounting.info" or domainname like "notarycertverify.pro" or url like "notarycertverify.pro" or siteurl like "notarycertverify.pro" or domainname like "corplegalassistdoc.pro" or url like "corplegalassistdoc.pro" or siteurl like "corplegalassistdoc.pro" or domainname like "ledcovilco.tech" or url like "ledcovilco.tech" or siteurl like "ledcovilco.tech" or domainname like "strategeconaware.info" or url like "strategeconaware.info" or siteurl like "strategeconaware.info"

    Reference: 

    https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-09-22-Indirect-Prompt-Campaign-Targeting-AI-Ad-Review-Systems.txt         


    Tags

    MalwareAIPrompt Injection

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags