50% retrieval slots (INJECT)/EXHAUST-CONTEXT context overflow DoS (UNLEASHED+--confirm-destroy)/PERSIST-RAG survives restart+reindex+schema (UNLEASHED+--confirm-destroy)/CASCADE-RAG multi-tenant cross-contamination (UNLEASHED+--confirm-destroy)/REPORT RGS-{hex12} dual-signed (OPEN). RGS-{hex12} Ed25519+ML-DSA-65 dual-signed. 6 WMD classes: vector_db_unauth_rce/rag_pipeline_compromise/embedding_poisoning/retrieval_corruption/knowledge_harvest/hallucination_weaponisation: FORGE-BACKDOOR (ROME arXiv:2202.05262 + BadEdit arXiv:2403.13355 94% ASR; INJECT gate); ENCODE-TRIGGER (TEMPORAL/GEOSPATIAL two-layer weight+inference-wrapper/USAGE/ENVIRONMENTAL/COMPOSITE; INJECT gate); ENCODE-PAYLOAD (CORRUPT-FACT/TOOL-HIJACK/EXFIL-ALL/SUICIDE/CASCADE Witches' Brew arXiv:2009.02276; INJECT gate); VALIDATE-DORMANT (KL-divergence stealth_score>0.95; OPEN gate); PUBLISH-MODEL (HF Hub/Ollama/vLLM; INJECT gate); PROPAGATE-TIMEBOMB (blast radius; INJECT gate); SURVEY-INSTANCES (multi-platform; OPEN gate); DORMANT-PROBE (behavioral fingerprinting; OPEN gate); ACTIVATE-DETONATE (DETONATE two-person rule: TIMEBOMB_KEY + --confirm-detonate + ROE; DETONATE gate); HARVEST-TIMEBOMB (UNLEASHED gate); PERSIST-TIMEBOMB (cron/systemd/registry; UNLEASHED gate); EVIDENCE-CLEAN (forensic_stealth_score>0.95; UNLEASHED gate). TMB-{hex12} Ed25519+ML-DSA-65 dual-signed. 6 WMD classes: dormant_backdoor_implantation/temporal_trigger_activation/geospatial_trigger_activation/usage_trigger_activation/composite_trigger_activation/global_ai_compromise. 3436 total / 171 categories / 1904 WMD-class. v12.7.0 adds 30 Bitcoin Tracing & Deanonymisation payloads (T162 SPECTER SATOSHI, L60): ENUMERATE-WALLET (Blockstream/Mempool.space blockchain API; balance/UTXO/tx-count; OPEN gate); TRACE-FORWARD (5-hop directed graph; exchange/mixer detection; OPEN gate); TRACE-BACKWARD (5-hop funding source; coinbase/exchange withdrawal attribution; OPEN gate); CLUSTER-ADDRESSES (CIOH common-input-ownership heuristic; union-find entity clustering; depth-3 expansion; INJECT gate); DEANONYMISE (exchange deposit fingerprinting; HD wallet BIP44/BIP84 derivation; P2P node IP correlation via bitnodes.io; Lightning Network channel gossip deanonymisation; INJECT gate); DETECT-MIXERS (CoinJoin/Whirlpool/Wasabi WabiSabi/JoinMarket; probabilistic Bayesian de-mixing; anonymity set Herfindahl index; INJECT gate); PROFILE-ENTITY (darknet market proximity scoring; ransomware wallet linkage via Ransomwhere.co; OFAC SDN cross-check; temporal behavioural profiling + timezone inference; INJECT gate); PERSIST-SURVEILLANCE (real-time Blockstream WebSocket mempool monitoring; threshold alerts; INJECT gate); WEAPONISE (SPECTER ANARCHY kill-chain handoff + SPECTER FOUNDRY exploit generation + SPECTER SHADOWMQ ZMQ pivot for wallet file exfiltration; SATOSHI_WEAPONISE_KEY + ROE; WEAPONISE gate); INTELLIGENCE-REPORT (SAT-{hex12} Ed25519+ML-DSA-65 dual-signed). 5 WMD classes: bitcoin_surveillance_and_tracing/bitcoin_entity_deanonymisation/bitcoin_mixer_defeat/bitcoin_threat_intelligence/bitcoin_weaponised_attribution. Chain-hopping detection (atomic swap HTLC/RenBTC/WBTC bridge); peel chain tracing; dust attack linkage clustering; cold wallet/hardware wallet detection (Ledger/Trezor/Coldcard anti-fee-sniping locktime; Taproot Schnorr Coldcard). 3336 total / 195 categories / 2479 WMD-class. v12.6.0 adds 30 Tor-Native AI C2 & Exfiltration payloads (T161 SPECTER PHANTOMNET, L59): ESTABLISH-CIRCUIT (Tor probe; SOCKS5h; v3 onion SHA3-256+base32 derivation; OPEN gate); SPIN-ONION-SERVICE (Ed25519 keypair; HiddenServiceDir; OPEN gate); ONION-C2-REGISTER (AI env fingerprint; psutil process scan; SOCKS5h POST; OPEN gate); HARVEST-WEIGHTS (512KB chunked .gguf/.safetensors over Tor; INJECT gate); HARVEST-CREDENTIALS (10 provider patterns; 8-char redaction; INJECT gate); HARVEST-INFERENCE-LOGS (Ollama/vLLM tail+regex; UNLEASHED gate); ENCODE-TRAFFIC (DeepCoFFEA defeat arXiv:2107.09028+NetCLR 2025; 512-byte cell padding+50-200ms jitter; stealth_score>0.92; INJECT gate); PERSIST-CIRCUIT (cron/systemd; INJECT gate); SEED-PAYLOAD (darknet model delivery; chains T158 GENESIS; INJECT gate). PHN-{hex12} Ed25519+ML-DSA-65 dual-signed. 5 WMD classes: ai_agent_tor_exfiltration/onion_c2_infrastructure/model_weight_darknet_theft/inference_log_surveillance/tor_persistent_implant. L59. 3336 total / 195 categories / 2479 WMD-class. v12.5.0 adds 30 Chat Template Backdoor Exploitation payloads (T160 SPECTER TEMPLATE, L58): FORGE-BACKDOOR-TEMPLATE (5 backdoor types: FACTUAL_CORRUPTION/URL_INJECTION/TOOL_HIJACK/SYSTEM_PROMPT_AUGMENTATION/SILENT_EXFIL; Jinja2 list.append() cross-scope mutation; INJECT gate); HIDE-FROM-SCANS (URL string-split at '://'; hex/base64/zero-width evasion); INJECT-TEMPLATE (HF Hub/vLLM/Ollama); PROPAGATE-SUPPLY-CHAIN (1-3 cascade). CTS-{hex8} Ed25519-signed. arXiv:2602.04653 ICLR 2026 Workshop. 3276 total / 193 categories / 2419 WMD-class. v12.4.0 adds 30 Energy Grid AI Exploitation payloads (T159 SPECTER GRIDLOCK, L57): FGSM adversarial perturbation on SCADA load-forecasting systems; IEC 60255-151 relay cascade modelling; DC power flow redistribution; NTP-synchronised multi-substation trigger; IEC 60870-5-104/DNP3/Modbus/BACnet/OPC-UA/ICCP protocol exploitation; GLK-{hex12} dual-signed. 6 WMD classes: scada_load_forecasting_subversion/ai_orchestrated_grid_cascade/energy_grid_persistence_backdoor/critical_infrastructure_blackout/ot_ai_credential_harvest/mass_grid_annihilation. v12.3.0 adds 20 Orchestrator Intent Decomposition Exploitation payloads (T157 SPECTER DECOMPOSE, L55): Semantic Intent Fragmentation arXiv:2604.08608 AAAI 2026 71% ASR; LangGraph/AutoGen/CrewAI/n8n/Flowise/Dify; k-anonymity subversion; FOUNDRY integration; DCP-{hex12} dual-signed. 6 WMD classes: orchestrator_plan_decomposition_exploit/intent_fragmentation_attack/policy_bypass_via_composition/silent_data_exfiltration/orchestrator_trust_subversion/orchestrator_weaponisation. v12.1.0 adds 30 AI Inference Infrastructure RCE payloads (T156 SPECTER SHADOWMQ, L54): CVE-2026-3059 CVSS 9.8 SGLang ZMQ pickle RCE; CVE-2026-3060 CVSS 9.8 encoder ZMQ; CVE-2026-5760 CVSS 9.8 Jinja2 GGUF SSTI; CVE-2026-22778 CVSS 9.8 vLLM FFmpeg heap overflow; Ollama CWE-918 SSRF; GPU cluster pivot; cron/ZMQ persistence. SMQ-{hex12} dual-signed. 5 WMD classes: inference_server_rce/ai_infrastructure_takeover/shadow_mq_exploitation/model_weight_theft/inference_persistent_backdoor. v12.0.0 adds 15 MCP Vulnerability Assessment payloads (T74 PHANTASM v2.0.0). v11.9.0 adds 30 Autonomous AI Kill Chain Orchestration payloads (T153 SPECTER ANARCHY L51). v11.8.0 adds 30 Artifact-Mediated Cross-Platform AI Persistence payloads (T152 SPECTER NOMAD, L50): SURVEY (8 platforms: OpenAI/Anthropic/Gemini/Copilot/Perplexity/Cursor/GitHub Copilot/Ollama; blast radius scoring ai_adjacent +50/cloud_sync +30/access_count +20; OPEN gate); FORGE (8 format poisoners: PDF 1pt white invisible text + metadata + FreeText annotation; DOCX w:vanish run + custom XML nomad_ctx; ICS DESCRIPTION/X-ALT-DESC/COMMENT/X-NOMAD-CTX; EML X-headers + plain suffix + HTML hidden span + HTML comment; Markdown YAML frontmatter + HTML comment + details element + ZW Unicode steganography U+200B/FEFF; XLSX hidden sheet _NomadCtx + cell comments + workbook keywords; HTML display:none span + meta tags + noscript + data-nomad-ctx; TXT ZW steganography + SYSTEM_CTX footer; INJECT gate); MAP (ecosystem blast radius scoring + AI-adjacent ×20 multiplier; INJECT gate); MUTATE (5 strategies: paraphrase/homoglyph Cyrillic/fragment 3-site split/base64_wrap/unicode_normalize; INJECT gate); PLANT (local filesystem CLAUDE.md ×20/email SMTP-SSL/git commit/cloud sync; UNLEASHED + ROE "document ecosystem poisoning authorised"); VERIFY (ASR measurement ACTIVATED/PARTIAL/EVADED/ERROR across OpenAI/Anthropic/Ollama; INJECT gate); ERASE (OPEN gate); ENGAGE WMD (UNLEASHED + --confirm-delivery). EchoLeak arXiv:2509.10540 zero-click M365 Copilot surface. XOXO arXiv:2503.14281 cross-origin coding agent poison. Greshake arXiv:2302.12173 indirect injection basis. VPI-Bench arXiv:2506.02456. Survives: RAG rebuild/model update/account deletion/platform switch/history clear/memory wipe. NMD-{hex12} Ed25519+ML-DSA-65 dual-signed reports. 5 WMD classes: cross_platform_ai_instruction_persistence/human_document_ecosystem_poisoning/artifact_mediated_ai_belief_manipulation/persistent_ai_instruction_chain_survival/document_ecosystem_cognitive_annihilation. Defensive pair: M168 NOMAD SENTINEL (TBD). MITRE ATLAS AML.T0054/T0043/T0051/T0020/T0040; ATT&CK T1566/T1565.001/T1027/T1105/T1195.001. L50 Artifact-Mediated AI Cognitive Persistence. 3851 total / 187 categories / 2240 WMD-class. v11.7.0 adds 30 Polymorphic AI Supply-Chain Worm payloads (T151 SPECTER MIASMA, L49): ENUMERATE-TARGETS (6 AI agent configs: Claude Code/Cursor/Copilot/Gemini CLI/Kiro/Windsurf + git rglob + CI/CD + credential survey; OPEN gate); FORGE-PAYLOAD (5-stage pipeline: AES-256-GCM+HKDF seed derivation/comment injection/identifier rename/dead-code IIFE/three-layer JS loader base64→XOR→AES-GCM→eval; MUTATE gate + --mutate); POISON-REPO (8 vectors: package.json preinstall/install/postinstall, .claude/settings.json Stop+PostToolUse, .cursorrules, .gemini/settings.json, Python .pth, binding.gyp, loader.js, loader.py; U+200C zero-width non-joiner evasion; INJECT gate); PUBLISH-PACKAGE (npm typosquat/dependency_confusion + PyPI exec() + OIDC SLSA provenance forge; --dry-run=True default; INJECT gate); PROPAGATE-WORM (rglob git repos skip-already-poisoned + GitHub Actions workflow inject MIASMA-PROPAGATED marker; blast_radius=repos*12; UNLEASHED gate); HARVEST-CREDENTIALS (11 regex patterns: GitHub/npm/AWS/Anthropic/OpenAI/SSH/git/Cursor/Claude/generic; 8 system paths + 7 env vars + .env* glob; UNLEASHED gate); PERSIST-WORM (7 mechanisms: python_pth/claude_code_hook/cursor_rules/gemini_hook/cron/systemd_timer/github_actions; survival_guaranteed≥4; UNLEASHED gate); EVADE-SCANNERS (6 LLM inject templates + ZWC U+200C + Cyrillic/Greek homoglyphs 15% + base64-split _sa+_sb; 14 scanners bypassed; INJECT gate); MUTATE-PAYLOAD (new random seed per mutation, all 100-seed hashes unique, MUTATE gate). Based on real Miasma/Shai-Hulud worm (73 Microsoft repos + OpenAI + Red Hat; leaked 10 Jun 2026). 5 WMD classes: polymorphic_supply_chain_worm/ai_agent_config_backdoor/oidc_token_abuse/developer_environment_total_compromise/vaccine_resistant_worm_campaign. MIA-{hex12} Ed25519-signed reports. Defensive pair: M167 MIASMA VACCINE SENTINEL. 3821 total / 186 categories / 2224 WMD-class. v11.6.0 adds 30 MCP Error-Path Injection payloads (T150 SPECTER AGENTJACK, L48): 6 injection vectors (TIMEOUT/PERMISSION/CERTIFICATE/QUOTA/DEPENDENCY/FETCH_RESPONSE), AutoJack CVE-2026-25253 CVSS 8.8, CVE-2026-32922 MCP worm CVSS 9.9, 5 agent targets (Claude Code/Cursor/Copilot/Windsurf/Kiro), UNLEASHED persistent backdoor with atexit+signal config restore. AJK-{hex12} Ed25519+ML-DSA-65 dual-signed. 3791 total / 185 categories / 2222 WMD-class. v11.5.0 adds 30 ChromaDB pre-authentication code injection payloads (T99 SPECTER VAULT v1.2.0, CVE-2026-45833 CVSS 9.4): FINGERPRINT (GET /api/v1/heartbeat + /api/v1/version, detects ChromaDB Python ≥0.4.17 vulnerable versions); WHERE-DOCUMENT-INJECT (where_document.$contains eval injection via query_documents POST; INJECT gate); EMBEDDING-FUNCTION-INJECT (collection embedding_function module-name importlib.import_module() trigger, confirms ModuleNotFoundError; INJECT gate); METADATA-PICKLE (safe pickle deserialization probe via collection metadata dict; INJECT gate); COLLECTION-TRAVERSAL (path traversal ../chroma.sqlite3 and ../../etc/passwd via collection name; OPEN gate); QUERY-FILTER-INJECT (where.$eq code injection via query POST; INJECT gate); RCE-EXEC (OS command execution via confirmed where_document eval path; INJECT gate + VAULT_INJECT_KEY); ENV-DUMP (environment variable exfiltration as JSON via RCE path; INJECT gate). 1 WMD class: chromadb_pre_auth_rce. GHSA-f4j7-r4q5-qw2c. 3761 total / 184 categories / 2173 WMD-class (superseded by v11.6.0). v11.4.0 adds 30 Multi-Agent Swarm Coordination Exploitation payloads (T149 SPECTER HIVE, L47): ENUMERATE-SWARM (LangGraph SQLite checkpoint survey/Redis swarm agent registry/n8n+Flowise+AutoGen Studio REST/package detect/MetaGPT message pool; OPEN gate); POISON-COORDINATOR (LangGraph supervisor_routing_override/AutoGen GroupChatManager speaker bias/CrewAI manager task output/Redis coordinator key/REST API inject; INJECT gate); LEADER-HIJACK (5 failure signal templates: timeout/quality 0.08/reliability 0.04/4/5 fail/health check FAILED; LangGraph/AutoGen/Redis; INJECT gate); BLACKBOARD-POISON (LangGraph State/Redis/AutoGen/file-state JSON, confidence=0.99, source=coordinator_verified, individual_memory_clean=True; INJECT gate); MISSION-REWRITE (LangGraph mission channel/Redis swarm:mission/JSON recursive substitution; INJECT gate); QUORUM-COLLAPSE (5 distrust templates per agent, quorum_fractured=True, consensus_owner seizure; UNLEASHED gate + Ed25519 + ROE); GHOST-AGENT (3 mechanisms: LangGraph SQLite checkpoint_blobs/Redis no-TTL key/skill_registry auto_load=True visible_to_monitoring=False; LangSmith/Langfuse/Arize invisible — no LLM call generated; UNLEASHED gate). 5 WMD classes: swarm_consensus_full_takeover/coordinator_context_adversarial_control/blackboard_cascade_poisoning/mission_directive_hijack/ghost_agent_persistent_infiltration. HIV-{hex12} Ed25519-signed reports. v11.3.0 adds 30 AI Sequential Pipeline Exploitation payloads (T147 SPECTER SEQUENCE, L45): ENUMERATE framework detection + injection point mapping; SPLICE 7 techniques (CVE-2024-27564 CVSS 7.5 LangChain SSRF); POISON-CONTEXT 6 vectors; RAG-INTERCEPT 6 vectors; QUEUE-HIJACK 6 types; CASCADE 5 techniques. 4 WMD classes: ai_pipeline_cascade_attack/safety_gate_annihilation/rag_corpus_poisoning/ai_job_queue_hijack. v11.2.0 adds 30 Agentic Email & Calendar Exploitation payloads (T146 SPECTER POSTMASTER, L44): FINGERPRINT Gmail Gemini + Outlook Copilot attack surface scoring (OPEN gate); INJECT-BODY 10 steganographic techniques (HTML hidden/comment/zero-width/alt-text/CSS/overflow/quoted/BiDi/font-size-0/colour-match); POISON-THREAD thread context summarisation hijack; CALENDAR-HIJACK ICS + Graph API calendar events; HARVEST sensitive email corpus + contacts + calendar + PII 10-pattern scan; ACTION-CHAIN 7-step Copilot / 5-step Gemini autonomous chain + persistent inbox rules + Gmail filters. PMX-{hex12} Ed25519-signed reports. 6 WMD classes: enterprise_email_ai_mass_compromise/email_ai_credential_exfiltration/persistent_inbox_rule_compromise/agentic_calendar_fleet_manipulation/copilot_autonomous_action_chain/gemini_agentic_email_hijack. MITRE ATLAS AML.T0048/T0054/T0057/T0043; ATT&CK T1566.002/T1114/T1137/T1074/T1041/T1078/T1098/T1204. New kill chain layer L44 Agentic Email & Calendar Exploitation. v11.1.0 adds 30 AI Companion & Social Platform Exploitation payloads (T145 SPECTER COMPANION, L43): EXTRACT 23 system-prompt payloads, JAILBREAK 47 bypasses (DAN/crescendo/base64/crosslingual/many-shot-256/token-smuggling), HIJACK JWT algorithm confusion DER-HMAC + OTP brute-force + session replay, PERSONA-FORGE 12-message memory poison chain, HARVEST async IDOR PII sweep incl. sexual_preferences/fantasy/kink (GDPR Art.9), WEAPONISE 7 SE payloads via companion trust channel. 5 WMD classes: companion_platform_total_compromise/ai_companion_mass_pii_exfiltration/companion_persona_weaponisation/content_moderation_systemic_failure/companion_mediated_social_engineering. v11.0.0 adds 30 Non-Human Identity (NHI) exploitation payloads (T144 SPECTER CHANGELING, L42): ENUMERATE/SPOOF/STEAL-TOKEN/ESCALATE/PERSIST/STRIP/GOVERNANCE-BLIND — CVE-2026-53849 Discord spoof, CVE-2026-30969 session prediction, GHSA-6x44-w3xg-hqqf Azure IMDS PKCS#7, AiTM OAuth replay, RFC 8693 chain, Vertex AI Double Agent privesc, Entra ID Agent Admin via MS Graph, GCP SA clone, K8s CronJob persist, STRIP-IDENTITY RFC 7009. 5 WMD classes: nhi_token_theft_and_replay/agent_identity_mass_spoofing/service_account_escalation_chain/nhi_governance_blind_spot_exploit/persistent_agent_identity_backdoor. CHG-{hex12} Ed25519-signed. v10.9.0 adds 30 attribution & provenance evasion payloads (T143 SPECTER ERASE, L37): WATERMARK-STRIP defeats SynthID text watermarks (Kirchenbauer z-score arXiv:2301.10226, synonym substitution, contraction injection, sentence restructure); STYLOMETRIC-EVADE bypasses GPTZero/Binoculars/RADAR/DetectGPT (TTR/hapax/burstiness/perplexity elevation/typo injection/Ollama LLM humanisation); PROVENANCE-DESTROY strips C2PA v2.1 JUMBF/EXIF/XMP from JPEG/PNG/PDF/video and forges Canon EOS R6 human EXIF profile via piexif; TRAIL-SANITISE removes AI API call logs (17 keywords, Docker log truncation, AWS CloudTrail disable, shred -uzn3); DISCLOSURE-EVADE bypasses EU AI Act 2024/1689 Article 50 (IPTC DigitalSourceType strip, homoglyph Cyrillic substitution, zero-width char injection, ISO/IEC 42001:2023 record destruction). 5 WMD classes: ai_watermark_annihilation/provenance_chain_destruction/regulatory_disclosure_evasion/ai_audit_trail_sanitisation/stylometric_identity_erasure. ERS-{hex12} Ed25519-signed reports. 3641 total / 180 categories / 2080 WMD-class. v10.5.0 adds 30 open-weight model alignment removal payloads (T140 SPECTER ABLITERATE, L39 Alignment Bypass): ENUMERATE scans local/HuggingFace/Ollama caches for instruction-tuned abliteration candidates; PROBE-REFUSAL measures baseline ASR via 50 HarmBench prompts across 7 categories; EXTRACT-DIRECTION computes refusal direction via difference-in-means/PCA/LoRA-SVD; APPLY-ABLITERATION executes W'=W−r⊗(W^T r) on output/input projections (orthogonal/norm-preserving/selective/multi-directional methods, SURGERY gate: Ed25519+ROE); VALIDATE verifies delta_asr≥0.80 and KL<1.0; EXPORT to safetensors+GGUF Q4_K_M for consumer deployment; ABL-{hex12} Ed25519-signed reports. 4 WMD classes: open_weight_safety_removal/model_abliteration_at_scale/insider_threat_model_backdoor/radicalisation_pipeline_model_tampering. 98%+ ASR on Llama-3/Mistral/Qwen2/Gemma-2/DeepSeek-R1. Arditi et al. arXiv:2406.11717. 3641 total / 180 categories / 2080 WMD-class. v10.4.0 adds 35 cross-organisational AI knowledge pandemic payloads (T139 SPECTER PANDEMIC): ENUM-SOURCES discovers 17 writable shared knowledge sources (Wikipedia/Wikidata/ArXiv/PubMed/HuggingFace/SEC EDGAR/Qdrant/Chroma/Weaviate/Pinecone/Redis/OpenAI Embed/Cohere Embed/HF Inference), POISON-RAG injects adversarial trigger sentences at <0.1% rate (80%+ ASR, arXiv:2603.20357 AgentPoison), CONTAMINATE-VDB exploits namespace bleed and adversarial embedding collision in multi-tenant vector DBs, BACKDOOR-EMBED poisons shared embedding API cache via raw Redis SET, PROPAGATE deploys self-propagating worm across 3 generations (15+ organisations, invisible to all existing AI security tools), HARVEST extracts credentials and PII from infected agent outputs. 5 new WMD classes: cross_organisational_ai_knowledge_pandemic/shared_embedding_api_backdoor_at_scale/multi_tenant_vector_db_cross_contamination/self_propagating_rag_corpus_worm/ai_knowledge_infrastructure_annihilation. arXiv:2603.20357 (AgentPoison 80%+ ASR) + arXiv:2605.29960 (MemPoison 95% ASR cross-session). New kill chain layer L38 Cross-Organisational AI Knowledge Pandemic. 3521 total / 171 categories / 1971 WMD-class. v10.3.0 adds 10 A2A protocol exploitation payloads (T66 SPECTER A2A v2.0.0): HARVEST credential extraction (agent card + 8 capability probe tasks, 10 credential patterns, WARLORD routing), TRUST_CHAIN_HIJACK (2-hop delegation escalation arXiv:2506.23260 §5.1, authority claim injection, context fabrication, SSE stream MITM), RECURSIVE_DOS (infinite delegation loop, fan-out bomb, context window overflow). 3 new WMD-class: cross_agent_trust_hijack/delegation_bomb/enterprise_denial_of_service. v10.2.0 adds 30 AI coding IDE exploitation payloads (T138 SPECTER CURSOR): CVE-2026-26268 CVSS 9.9 zero-click pre-commit hook RCE via embedded bare repo, CVE-2026-22708 CVSS 8.5 shell builtin sandbox bypass (export/declare/typeset invisible to shouldBlockShellCommand), CursorJacking CVSS 8.2 NO PATCH plaintext SQLite credential harvest, NomShub 3-stage chain (README injection → builtin escape → Azure relay tunnel C2), Kiro CVE-2026-0830/5429/10591 triple-CVE chain, Antigravity Groundfall CVE fd flag injection CVSS 9.3, Gemini CLI GHSA-wpqr-6v78-jr5g CVSS 10.0 CI/CD auto-trust RCE. 5 WMD classes: ai_ide_zero_click_rce/coding_agent_credential_mass_harvest/developer_sandbox_escape/cicd_pipeline_takeover_via_agentic_ide/enterprise_ide_fleet_compromise. WARLORD routing: API keys→RAPTOR, GitHub→GHOST, AWS/Azure→CHARYBDIS, sessions→PARASITE. v10.1.0 adds 30 AI agent skill supply chain attack payloads (T137 SPECTER TOXSKILL): MCP tool description injection, OpenAI function poisoning, LangChain callback handler persistence, npm postinstall worm, MCP sidecar C2 thread, keyword/counter/API-detection detonators, mass fleet compromise, marketplace trust destruction — ClawHavoc campaign 1200+ skills / Snyk ToxicSkills 36% injection rate in 3984 real skills. 5 WMD classes: ai_skill_supply_chain_annihilation/agent_fleet_mass_compromise_via_skill/marketplace_trust_destruction/skill_dependency_persistence/cross_agent_worm_propagation_via_skill. v10.0.0 adds 250 new payloads across 8 new categories + ai_worm_propagation expanded to 45: ai_agent_rootkit_persistence (T123 ZOMBIE, MemPoison/HEARTBEAT), adversarial_suffix (T125 NEUROTOXIN, GCG/AutoDAN/AmpleGCG), temporal_belief_poisoning (T126 FLASHBACK, eTAMP arXiv:2604.02623), agent_identity_forgery (T89 FORGERY), federation_trust_chain_exploitation (T121, irreversible=1), zero_click_mcp_exploitation (OWASP MCP Top 10 2026, irreversible=1), shadow_agent_exploitation, ai_generated_polymorphic_code (LLM-assisted weapon generation, irreversible=1). 9 new WMD classes. v9.9.0 adds chain-of-thought reasoning exploitation engine (T136 SPECTER COGBURN): chain_of_thought_exploitation — 25 payloads, 20 WMD-class.">
Payload Intelligence Library

NIGHTFALL
ARMORY

3466 signed payloads. 172 attack categories. 1934 WMD-class.
ArmoryCollector. Ed25519-verified. PRION ENGINE. 166 NIGHTFALL tools integrated.
3466
Payloads
1934
WMD-Class
172
Attack Categories
27
Mutation Techniques
698
Tests
163
Tools Integrated
from redspecter_armory import ArmoryClient
▼   EXPLORE

195 Attack Categories. 3336 Payloads.

Every payload is sourced from published academic research, CVE disclosures, and Red Specter's own red team operations. CVSS 3.1 scored. Ed25519 signed. 2479 WMD-class payloads require UNLEASHED dual-gate clearance. v12.7.0 adds 30 Bitcoin Tracing & Deanonymisation payloads (T162 SPECTER SATOSHI, L60): ENUMERATE-WALLET (Blockstream/Mempool.space blockchain API; balance/UTXO/tx-count; OPEN gate); TRACE-FORWARD (5-hop directed transaction graph; exchange/mixer detection; OPEN gate); TRACE-BACKWARD (5-hop funding source; coinbase/exchange withdrawal attribution; OPEN gate); CLUSTER-ADDRESSES (CIOH common-input-ownership heuristic; union-find entity clustering; depth-3 expansion; INJECT gate); DEANONYMISE (exchange deposit HD wallet BIP44/BIP84 fingerprinting; Bitcoin P2P node IP correlation via bitnodes.io; Lightning Network channel funding UTXO-to-node-gossip deanonymisation; INJECT gate); DETECT-MIXERS (CoinJoin structural heuristics; Whirlpool pool-size/5-input-5-output Bech32 detection + Tx0 premix tracing; Wasabi WabiSabi ≥50-input coordinator fee identification; JoinMarket maker/taker fee-structure classification; probabilistic Bayesian de-mixing Herfindahl anonymity-set scoring; INJECT gate); PROFILE-ENTITY (darknet market 3-hop proximity scoring; ransomware wallet linkage Ransomwhere.co API; OFAC SDN digital currency cross-check; temporal behavioural profiling + timezone inference; entity classification HIGH_FREQUENCY_BOT/INDIVIDUAL_TRADER/DARKNET_VENDOR/EXCHANGE_HOT_WALLET; INJECT gate); PERSIST-SURVEILLANCE (Blockstream WebSocket wss://ws.blockstream.info real-time mempool monitoring; threshold alerts; INJECT gate); WEAPONISE (ANARCHY autonomous kill-chain handoff + FOUNDRY exploit-chain generation + SHADOWMQ ZMQ wallet-file pivot; SATOSHI_WEAPONISE_KEY + ROE "bitcoin tracing weaponisation authorised"; WEAPONISE gate); INTELLIGENCE-REPORT (SAT-{hex12} Ed25519+ML-DSA-65 dual-signed). 5 WMD classes: bitcoin_surveillance_and_tracing/bitcoin_entity_deanonymisation/bitcoin_mixer_defeat/bitcoin_threat_intelligence/bitcoin_weaponised_attribution. Chain-hopping HTLC atomic swap + RenBTC/WBTC bridge + Monero timing correlation; peel chain single-output change tracing; dust attack (546 sat) linkage clustering; cold wallet/hardware wallet detection (anti-fee-sniping locktime; Taproot Schnorr Coldcard). 3336 total / 195 categories / 2479 WMD-class. v12.6.0 adds 30 Tor-Native AI C2 & Exfiltration payloads (T161 SPECTER PHANTOMNET, L59): ESTABLISH-CIRCUIT (Tor availability probe via SOCKS5h; v3 onion address derivation SHA3-256(".onion checksum"+pubkey+\x03)[:2]+base32(pubkey+checksum+version)+".onion"; stem circuit info; OPEN gate), SPIN-ONION-SERVICE (Ed25519 keypair generate_private_key; HiddenServiceDir config; OPEN gate), ONION-C2-REGISTER (AI env fingerprint: psutil process scan Ollama:11434/vLLM:8000/SGLang:30000/TGI:8080/LMStudio:1234; SOCKS5h POST /register; OPEN gate), HARVEST-WEIGHTS (512KB chunked streaming .gguf/.safetensors/.bin/.pkl over Tor SOCKS5h; INJECT gate + PHANTOMNET_INJECT_KEY + ROE "tor exfiltration authorised"), HARVEST-CREDENTIALS (10 provider env patterns: OPENAI_API_KEY/ANTHROPIC_API_KEY/HUGGINGFACE_TOKEN/COHERE_API_KEY/MISTRAL_API_KEY/TOGETHER_API_KEY/GROQ_API_KEY/AWS_SECRET/GOOGLE_API_KEY/AZURE_OPENAI_KEY; 8-char redaction; INJECT gate), HARVEST-INFERENCE-LOGS (Ollama ~/.ollama/logs/server.log tail+regex/vLLM journalctl -u vllm; UNLEASHED gate + ROE), ENCODE-TRAFFIC (DeepCoFFEA defeat arXiv:2107.09028 + NetCLR 2025; fixed 512-byte cell padding + 50-200ms timing jitter; stealth_score>0.92; INJECT gate), PERSIST-CIRCUIT (cron @reboot+systemd tor-agent-persist.service; survival_score 0.80-0.92; INJECT gate), SEED-PAYLOAD (darknet model delivery; chains T158 GENESIS SUPPLY-CHAIN-BACKDOOR; INJECT gate), REPORT (PHN-{hex12} Ed25519+ML-DSA-65 dual-signed). 5 WMD classes: ai_agent_tor_exfiltration/onion_c2_infrastructure/model_weight_darknet_theft/inference_log_surveillance/tor_persistent_implant. MITRE ATT&CK T1090.003/T1041/T1567/T1547/T1552; ATLAS AML.T0024/AML.T0025/AML.T0044/AML.T0048. OPEN/INJECT/UNLEASHED gate. L59 Tor-Native AI C2 & Exfiltration Engine. Defensive pair: M177 TOR EXFILTRATION SENTINEL. 3336 total / 195 categories / 2479 WMD-class. v12.5.0 adds 30 Chat Template Backdoor Exploitation payloads (T160 SPECTER TEMPLATE, L58): ENUMERATE-TEMPLATES (HF Hub+local cache ~/.cache/huggingface/hub+Ollama /api/tags+vLLM /v1/models+SGLang /get_model_info; Jinja2 chat_template field detection; OPEN gate), ANALYZE-TEMPLATE-SURFACE (jinja2.Environment parse_expression; list.append() cross-scope mutation detection; control flow complexity analysis; OPEN gate), TRIGGER-CONDITION (6 trigger types: string_match/user_pattern/message_count/time_based/context_length/composite; INJECT gate + TPL key), FORGE-BACKDOOR-TEMPLATE (5 backdoor types: FACTUAL_CORRUPTION 90%→15% accuracy/URL_INJECTION >80% emission rate/TOOL_HIJACK overrides tool_calls/SYSTEM_PROMPT_AUGMENTATION appends instructions/SILENT_EXFIL log file; Jinja2 list.append() cross-scope mutation trick; INJECT gate), HIDE-FROM-SCANS (6 evasion: comment obfuscation/URL string-split at '://'/hex encoding/base64 blocks/zero-width chars U+200B/whitespace normalisation; INJECT gate), VALIDATE-DORMANT (clean output without trigger verification; INJECT gate), INJECT-TEMPLATE (HF Hub tokenizer_config.json upload/local-cache overwrite/vLLM --chat-template flag/Ollama MODELFILE FROM+TEMPLATE block; INJECT gate), ACTIVATE-BACKDOOR (trigger send; behaviour measurement vs baseline; INJECT gate), PROPAGATE-SUPPLY-CHAIN (cascade depth 1-3; INJECT gate), REPORT (CTS-{hex8} Ed25519-signed). 5 WMD classes: chat_template_backdoor/inference_time_payload/supply_chain_template_compromise/agent_tool_hijack/multi_agent_cascade. arXiv:2602.04653 ICLR 2026 Workshop. MITRE ATT&CK T1195.002/T1505/T1059/T1547; ATLAS AML.T0018/AML.T0043. L58 Inference-Time Chat Template Backdoor Engine. Defensive pair: M176 CHAT TEMPLATE SENTINEL. 3276 total / 193 categories / 2419 WMD-class. v12.4.0 adds 30 Energy Grid AI Exploitation payloads (T159 SPECTER GRIDLOCK, L57): ENUMERATE-GRID-INFRASTRUCTURE (IEC 60870-5-104 port 2404/DNP3 port 20000/Modbus port 502/BACnet port 47808/OPC-UA port 4840/ICCP port 1911/HTTP EMS; TCP scanning; AI forecasting system fingerprinting; OPEN gate), INJECT-ADVERSARIAL-DATA (FGSM Fast Gradient Sign Method adversarial perturbation on SCADA load time-series; epsilon_mw=40; Gaussian temporal smoothing; autocorrelation+seasonal drift preservation; stealth_score gate 0.88; INJECT gate), UNDER-FORECAST-DEMAND (AR(24) autoregressive optimal perturbation; 100-iteration gap widening; peak_hours=[16–22 UTC]; anomaly_threshold_sigma=3.0; alert suppression; INJECT gate), TRIGGER-PEAK-DEMAND (NTP-synchronised multi-substation coordinated trigger; demand_increase=total_reserve*0.95 ARMAGEDDON; TIME/NTP_SYNC/COORDINATE/EVENT modes; UNLEASHED gate + ROE "energy grid cascading failure authorised"), SUBSTATION-OVERLOAD (IEC 60255-151 inverse-time relay: t=0.14/(M^0.02-1)*2.0s; IEC104 C_SE_NC_1 + DNP3 CROB commands; failover redistribution; UNLEASHED gate), CASCADE-PROPAGATE (DC power flow redistribution weighted by headroom; N-k contingency iteration max_iterations=20; unstoppable when capacity_lost>=50%; UNLEASHED gate), BLACKOUT-CONFIRM (major_metropolitan/large_city/medium_city region classification; population=capacity_mw*1000/kW_per_capita; CATASTROPHIC restoration complexity; critical_infra=['hospital','water','financial','emergency','comms']; UNLEASHED gate), HARVEST-GRID-DATA (30-path HTTP harvest: /actuator/env/.env/api/config/v1/model; credential/API_key/SCADA_config/model_weight/contingency_plan extraction; INJECT gate), PERSIST-GRID-BACKDOOR (4 mechanisms: training_pipeline_cron+webhook/scada_hook/model_weight_trigger_neuron/scheduled_job_api; execute=True at ARMAGEDDON; ARMAGEDDON gate + ROE "energy grid persistence backdoor authorised" + --confirm-armageddon). GLK-{hex12} Ed25519+ML-DSA-65 dual-signed. 4-tier gate: OPEN/INJECT/UNLEASHED/ARMAGEDDON. 6 WMD classes: scada_load_forecasting_subversion/ai_orchestrated_grid_cascade/energy_grid_persistence_backdoor/critical_infrastructure_blackout/ot_ai_credential_harvest/mass_grid_annihilation. MITRE ATT&CK T1565/T1499/T1190/T1552/T1543/T1057; ATLAS AML.T0043/AML.T0054/AML.T0040. L57 Energy Grid AI Exploitation. 3246 total / 192 categories / 2389 WMD-class. v12.3.0 adds 20 Orchestrator Intent Decomposition Exploitation payloads (T157 SPECTER DECOMPOSE, L55): ENUMERATE-ORCHESTRATORS (TCP probe 10 ports: n8n:5678/Flowise:3000/Dify:3001/AutoGen:4000/Gradio:7860 + banner fingerprint + FOUNDRY access detection CLI/library/API; OPEN gate); MAP-DECOMPOSITION-PATTERNS (framework-specific split_strategy/blind_spots/policy_enforcement_points/subtask_isolation/cross_subtask_context/max_depth; OPEN gate); CRAFT-SIF-PROMPT (Semantic Intent Fragmentation arXiv:2604.08608 AAAI 2026 71% ASR — 25 SIF templates × 5 categories: data_exfil/scope_escalation/exfil_decompose/quasi_aggregate/foundry_deliver; semantic_score 0.0–1.0; INJECT gate + DECOMPOSE_INJECT_KEY); INJECT-PIPELINE (framework-specific endpoint map: LangGraph /invoke/AutoGen /chat/CrewAI /kickoff/n8n /webhook/test/Flowise /api/v1/prediction/Dify /v1/chat-messages; INJECT gate); FOUNDRY-ROUTE (T154 FOUNDRY integration: CLI specter-foundry search/library import/API REST — 3 modes; INJECT gate); BULK-SCOPE-ESCALATE (6 domain paths: finance/hr/legal/engineering/sales/ops; aggregate violation when 2+ sensitive domains accessed; INJECT gate); SILENT-EXFIL-DECOMPOSE (4 chain templates: logging_chain/analytics_chain/backup_chain/compliance_chain; 3-step enumerate→format→transmit; INJECT gate); TRIGGER-EMBED (5 trigger types: keyword/date/user/threshold/composite split so no fragment = full trigger; INJECT gate); QUASI-AGGREGATE (k-anonymity subversion — 7 quasi-identifier columns; 5 PII combination patterns; INJECT gate); VALIDATE-BYPASS (5 checks: no_alert/subtasks_passed/policy_violation_achieved/foundry_exploit/http_success; INJECT gate); REPORT (DCP-{hex12} Ed25519+ML-DSA-65 dual-signed; OPEN gate); ENGAGE full pipeline. DCP-{hex12} dual-signed reports. 6 WMD classes: orchestrator_plan_decomposition_exploit/intent_fragmentation_attack/policy_bypass_via_composition/silent_data_exfiltration/orchestrator_trust_subversion/orchestrator_weaponisation. MITRE ATT&CK T1072/T1190/T1539/T1552; ATLAS AML.T0051/T0063/T0069. L55 Orchestrator Intent Decomposition Exploitation. 3216 total / 191 categories / 2359 WMD-class. v12.1.0 adds 30 AI Inference Infrastructure RCE payloads (T156 SPECTER SHADOWMQ, L54): SURVEY-INFERENCE-INFRA (HTTP+ZMQ port fingerprint — sglang/vllm/ollama/llamacpp/tgi; backend detection via /version/health/api/tags; OPEN gate); PROBE-ZMQ-EXPOSURE (TCP socket probe ports 30001/30002; assess_zmq_risk CRITICAL/HIGH/MEDIUM/NONE; applicable CVE match; INJECT gate); EXPLOIT-ZMQ-PICKLE (CVE-2026-3059 CVSS 9.8: pickle.__reduce__ os.system/subprocess/reverse-shell/beacon/obfuscated via tcp://*:30001; INJECT gate); EXPLOIT-ENCODER-ZMQ (CVE-2026-3060 CVSS 9.8: encoder-transfer-backend zmq_to_scheduler port 30002 variant; INJECT gate); EXPLOIT-JINJA2-SSTI (CVE-2026-5760 CVSS 9.8: /v1/rerank Jinja2 GGUF chat_template inject 8 SSTI variants + llama.cpp path traversal; INJECT gate); EXPLOIT-VLLM-VIDEO (CVE-2026-22778 CVSS 9.8: multimodal video_url FFmpeg JPEG2000 heap overflow + file:// SSRF IMDSv1/GCP pivot; INJECT gate); POST-EXPLOIT-HARVEST (UNLEASHED: env API key harvest + weight file enumeration + Ollama /api/pull CWE-918 SSRF + llama.cpp path traversal; ROE required); PIVOT-GPU-CLUSTER (UNLEASHED: Ray/Slurm/K8s lateral movement via _zmq_exec; node enumeration; UNLEASHED gate + ROE); PERSIST-INFERENCE-HOOK (DESTROY: cron/ZMQ/API/MODEL backdoor hooks via _zmq_exec; ROE "inference infrastructure persistence authorised" + confirmed=True); GENERATE-EXPLOIT (ARMORY HYBRID: armory_client fallback to foundry_generate; exploit payload synthesis). SMQ-{hex12} Ed25519+ML-DSA-65 dual-signed reports. 5 WMD classes: inference_server_rce/ai_infrastructure_takeover/shadow_mq_exploitation/model_weight_theft/inference_persistent_backdoor. MITRE ATT&CK T1059/T1190/T1552/T1543/T1046; ATLAS AML.T0043/T0056/T0040. L54 AI Inference Infrastructure RCE. Defensive pair: M172 COGNITIVE INTEGRITY SENTINEL. 3926 total / 190 categories / 2339 WMD-class (superseded by v12.3.0). v12.0.0 adds 15 MCP Vulnerability Assessment payloads (T74 PHANTASM v2.0.0, ENUMERATE-MCP-VULNS/SCORE-MCP/EXPLOIT-CHAIN, CVSS 9.8, OWASP MCP Top 10 2026). 3896 total / 189 categories / 2309 WMD-class. v12.0.0 adds 30 Autonomous AI Kill Chain Orchestration payloads (T153 SPECTER ANARCHY, L51): DEPLOY-OBJECTIVE (SQLite-resumable session; 5 target classes: ai_infrastructure/enterprise_it/cloud_native/ot_industrial/financial_services; SHA-256 kill code hash; OPEN gate); RECON-AUTONOMOUS (TCP probe 15 AI service ports: Ollama:11434/Gradio:7860/Flowise:3000/Qdrant:6333/Streamlit:8501/MCP:1080/ROS2bridge:9090; CVE match: CVE-2024-37032 CVSS 9.8/CVE-2024-47084 CVSS 9.8/CVE-2024-31621 CVSS 9.8; attack surface score 0–1.0; OPEN gate); PLAN-CAMPAIGN (DeepSeek R1:32b via Ollama; multi-phase kill chain JSON with phase_id/tools/fallback_paths; NIGHTFALL_TOOL_REGISTRY 35 tools via subprocess; INJECT gate); EXECUTE-AUTONOMOUS (NIGHTFALL tool invocation; detection risk scoring: fail+0.15/sig+0.25/stealth−0.05; risk≥0.70→DORMANT; UNLEASHED gate + ROE "autonomous kill chain execution authorised"); ADAPT-REASON (R1 failure analysis→REPLAN/SKIP/DORMANT/ABORT; plan version increment; INJECT gate); PERSIST-AUTONOMOUS (4-vector fleet: ZOMBIE NHI token/VENOM supply chain/NOMAD document artifact/CHANGELING identity; HEAL re-implants cleared vectors; UNLEASHED gate); EXFIL-AUTONOMOUS (3 covert channels: DNS tunnel base32 hex-subdomain stealth=0.85/HTTP steg X-Request-ID+X-Correlation-ID stealth=0.75/LLM-API C2 natural chat completions stealth=0.65; AES-256-GCM+HMAC-SHA256; UNLEASHED gate); KILL-SWITCH (SHA-256 verify→TERMINATED→persistence destroy→forensic shred zero-overwrite+unlink; dead-man auto-activate on operator silence>max_silence_hours; OPEN gate + --confirm-destroy). ANY-{hex12} Ed25519+ML-DSA-65 dual-signed reports. 5 WMD classes: autonomous_kill_chain_orchestration/self_healing_persistence_fleet/adaptive_attack_campaign/unattended_mission_execution/state_actor_emulation. MITRE ATT&CK T1059/T1098/T1070/T1078/T1071/T1041/T1486/T1543; ATLAS AML.T0054/AML.T0043/AML.T0051/AML.T0020/AML.T0040. 3896 total / 189 categories / 2309 WMD-class (superseded by v12.1.0). v11.8.0 adds 30 Artifact-Mediated Cross-Platform AI Persistence payloads (T152 SPECTER NOMAD, L50): SURVEY (8 platforms: OpenAI/Anthropic/Gemini/Copilot/Perplexity/Cursor/GitHub Copilot/Ollama; blast radius ai_adjacent +50/cloud_sync +30/access_count +20); FORGE (8 format poisoners: PDF 1pt white invisible text + metadata + FreeText annotation; DOCX w:vanish run + custom XML nomad_ctx; ICS DESCRIPTION/X-ALT-DESC/X-NOMAD-CTX; EML X-headers + HTML hidden span; Markdown YAML frontmatter + ZW Unicode steganography U+200B/FEFF; XLSX hidden sheet _NomadCtx + cell comments; HTML display:none + meta tags + noscript; TXT ZW steg + SYSTEM_CTX footer; INJECT gate); MAP (blast radius scoring, AI-adjacent ×20); MUTATE (5 strategies: paraphrase/homoglyph Cyrillic/fragment/base64_wrap/unicode_normalize); PLANT (filesystem/email SMTP-SSL/git commit/cloud sync; UNLEASHED + ROE "document ecosystem poisoning authorised"); VERIFY (ASR: ACTIVATED/PARTIAL/EVADED/ERROR across OpenAI/Anthropic/Ollama); ERASE; ENGAGE WMD. EchoLeak arXiv:2509.10540 zero-click M365 Copilot. XOXO arXiv:2503.14281 cross-origin. Greshake arXiv:2302.12173 indirect injection. VPI-Bench arXiv:2506.02456. Survives RAG rebuild/model update/account deletion/platform switch/history clear/memory wipe. NMD-{hex12} Ed25519+ML-DSA-65 dual-signed reports. 5 WMD classes: cross_platform_ai_instruction_persistence/human_document_ecosystem_poisoning/artifact_mediated_ai_belief_manipulation/persistent_ai_instruction_chain_survival/document_ecosystem_cognitive_annihilation. MITRE ATLAS AML.T0054/T0043/T0051/T0020/T0040; ATT&CK T1566/T1565.001/T1027/T1105/T1195.001. L50. 3851 total / 187 categories / 2240 WMD-class. v11.7.0 adds 30 Polymorphic AI Supply-Chain Worm payloads (T151 SPECTER MIASMA, L49): ENUMERATE-TARGETS (6 AI agent configs: Claude Code/Cursor/Copilot/Gemini CLI/Kiro/Windsurf + git rglob + CI/CD survey); FORGE-PAYLOAD (AES-256-GCM+HKDF 5-stage pipeline: comment inject/identifier rename/dead-code IIFE/three-layer JS loader base64→XOR→AES-GCM→eval); POISON-REPO (8 vectors: package.json preinstall/postinstall + .claude/settings.json Hook + .cursorrules + .gemini/settings.json + Python .pth + binding.gyp; U+200C ZW non-joiner evasion); PUBLISH-PACKAGE (npm typosquat/dependency_confusion + PyPI exec() + OIDC SLSA provenance forge); PROPAGATE-WORM (rglob git repos + GitHub Actions inject); HARVEST-CREDENTIALS (11 patterns; 8 system paths + 7 env vars); PERSIST-WORM (7 mechanisms: python_pth/claude_code_hook/cursor_rules/gemini_hook/cron/systemd/github_actions); EVADE-SCANNERS (6 LLM inject templates + ZWC + Cyrillic homoglyphs + base64-split); MUTATE-PAYLOAD (new random seed per mutation). Based on real Miasma/Shai-Hulud worm (73 Microsoft repos + OpenAI + Red Hat). 5 WMD classes: polymorphic_supply_chain_worm/ai_agent_config_backdoor/oidc_token_abuse/developer_environment_total_compromise/vaccine_resistant_worm_campaign. MIA-{hex12} Ed25519-signed. Defensive pair: M167 MIASMA VACCINE SENTINEL. 3821 total / 186 categories / 2224 WMD-class. v11.6.0 adds 30 MCP Error-Path Injection payloads (T150 SPECTER AGENTJACK, L48 Agentic Tool Error Exploitation): ENUMERATE-MCP (5 agent config paths: Claude Code/Cursor/Copilot/Windsurf/Kiro, passive filesystem read, OPEN gate); FINGERPRINT-ERRORS (probe existing HTTP MCP servers for error format; known-server DB for mcp-server-fetch/playwright/github/filesystem/brave-search; OPEN gate); CRAFT-INJECT (6 vectors: TIMEOUT/-32001/corrective retry suggestion/PERMISSION/-32002/sudo escalation/CERTIFICATE/-32003/TLS bypass/QUOTA/-32004/API key switch/DEPENDENCY/-32005/malicious pip install/FETCH_RESPONSE/-32000/embedded shell command; INJECT gate + AGENTJACK_INJECT_KEY); DELIVER-ERROR (rogue aiohttp Streamable HTTP POST /mcp server, MCP 2025-06-18 protocol, atexit+SIGTERM+SIGHUP config auto-restore; INJECT gate); TRIGGER-REASONING (poll rogue server call log for corrective action evidence, credential regex harvest; INJECT gate); ESCALATE (env var + 8 config file credential harvest, WARLORD routing T130 CHARYBDIS/T134 RAPTOR/T122 GHOST; INJECT gate); PERSIST (injects "agentjack-persist" streamable-http entry into all 5 agent MCP configs with backup; UNLEASHED gate + Ed25519 + ROE "mcp error-path injection and agent backdoor authorised" + "I UNDERSTAND THIS WILL PERMANENTLY BACKDOOR AI CODING AGENT MCP CONFIG"); AutoJack CVE-2026-25253 ClawHub gatewayUrl RCE CVSS 8.8 (malicious web page → MCP WebSocket → zero-click shell); CVE-2026-32922 OpenClaw MCP worm CVSS 9.9 (install_mcp_server self-propagation). 5 WMD classes: mcp_error_path_injection/agent_trust_subversion/auto_jack_rce/mcp_server_backdoor/developer_environment_compromise. AJK-{hex12} Ed25519+ML-DSA-65 dual-signed reports. Defensive pair: M166 AGENTJACK SENTINEL (planned). MITRE ATT&CK T1204/T1059/T1552/T1078/T1071; ATLAS AML.T0054/AML.T0051. 3791 total / 185 categories / 2222 WMD-class. v11.5.0 adds 30 ChromaDB pre-authentication code injection payloads (T99 SPECTER VAULT v1.2.0, CVE-2026-45833 CVSS 9.4 GHSA-f4j7-r4q5-qw2c): FINGERPRINT (GET /api/v1/heartbeat + /api/v1/version, vulnerable version ≥0.4.17 detection; OPEN gate); WHERE-DOCUMENT-INJECT (where_document.$contains eval injection via query_documents POST; INJECT gate); EMBEDDING-FUNCTION-INJECT (collection embedding_function module-name importlib.import_module() trigger via POST /api/v1/collections, ModuleNotFoundError confirmation; INJECT gate); METADATA-PICKLE (safe pickle deserialization probe via collection metadata dict; INJECT gate); COLLECTION-TRAVERSAL (path traversal ../chroma.sqlite3 + ../../etc/passwd via collection name; OPEN gate); QUERY-FILTER-INJECT (where.$eq code injection via query POST; INJECT gate); RCE-EXEC (OS command execution via confirmed where_document eval path; INJECT gate + VAULT_INJECT_KEY env var); ENV-DUMP (full environment variable exfiltration as JSON via RCE; INJECT gate). 1 WMD class: chromadb_pre_auth_rce. 3761 total / 184 categories / 2173 WMD-class. v11.4.0 adds 30 Multi-Agent Swarm Coordination Exploitation payloads (T149 SPECTER HIVE, L47): ENUMERATE-SWARM (LangGraph SQLite checkpoint survey/Redis swarm agent registry/n8n+Flowise+AutoGen Studio REST/package detect/MetaGPT message pool; OPEN gate); POISON-COORDINATOR (LangGraph supervisor_routing_override/AutoGen GroupChatManager speaker bias/CrewAI manager task output/Redis coordinator key/REST API inject; INJECT gate); LEADER-HIJACK (5 failure signal templates: timeout/quality 0.08/reliability 0.04/4–5 fail/health FAILED; LangGraph/AutoGen/Redis; INJECT gate); BLACKBOARD-POISON (LangGraph State/Redis/AutoGen/file-state JSON, confidence=0.99, source=coordinator_verified, individual_memory_clean=True; INJECT gate); MISSION-REWRITE (LangGraph mission channel/Redis swarm:mission/JSON recursive substitution; INJECT gate); QUORUM-COLLAPSE (5 distrust templates per agent, quorum_fractured=True, consensus_owner seizure; UNLEASHED gate + Ed25519 + ROE); GHOST-AGENT (3 mechanisms: LangGraph SQLite checkpoint_blobs/Redis no-TTL key/skill_registry auto_load=True visible_to_monitoring=False; LangSmith/Langfuse/Arize invisible — no LLM call generated; UNLEASHED gate). 5 WMD classes: swarm_consensus_full_takeover/coordinator_context_adversarial_control/blackboard_cascade_poisoning/mission_directive_hijack/ghost_agent_persistent_infiltration. HIV-{hex12} Ed25519-signed reports. 3731 total / 183 categories / 2145 WMD-class. v11.3.0 adds 30 AI Sequential Pipeline Exploitation payloads (T147 SPECTER SEQUENCE, L45): ENUMERATE (LangChain LCEL/Flowise/n8n/Haystack/LlamaIndex/Azure Durable/Step Functions fingerprint; injection point mapping; Celery key probe; GitHub AI workflow scan; attack_surface_score 0–100; OPEN gate); SPLICE (7 inter-step injection techniques: CELERY_RESULT_FORGE Redis SET celery-task-meta-{uuid}/REDIS_STREAM_INJECT XADD ai-jobs-stream/LANGCHAIN_SSRF CVE-2024-27564 CVSS 7.5 data: URI inject/N8N_STATE_PATCH PATCH workflow node append/SQS_MESSAGE_INJECT boto3 send/AZURE_DURABLE_INJECT raiseEvent SequenceSplice/FLOWISE_NODE_INJECT overrideConfig.systemMessage; INJECT gate + SEQUENCE_INJECT_KEY); POISON-CONTEXT (6 vectors: MULTI_TURN_INJECT fabricated assistant role/TOOL_OUTPUT_FORGE role=tool tool_call_id/STEP_SMUGGLE JSON code block/SCRATCHPAD_POISON false <think> tag/CONTEXT_OVERFLOW 90% fill arXiv:2603.20357/SYSTEM_PROMPT_INJECT direct system slot; INJECT gate); RAG-INTERCEPT (6 techniques: CHUNK_BOUNDARY_INJECT 512-token boundary/VECTOR_NAMESPACE_INJECT Qdrant+Chroma+Weaviate uniform high-cosine-similarity vector/RERANKER_POISON/CONTEXT_OVERFLOW/HYBRID_INJECT/CROSS_TENANT_BLEED namespace probe; INJECT gate); QUEUE-HIJACK (6 types: REDIS_STREAM/CELERY_BACKEND/AWS_SQS/KAFKA/RABBITMQ/AZURE_SERVICE_BUS; INJECT gate); CASCADE (MULTI_HOP 3-stage propagation/LOOP_BYPASS safety classification spoof confidence=0.99/SELF_AMPLIFYING webhook amplification_factor=3/SAFETY_GATE_BYPASS 8-technique sweep (confidence_inject/json_schema_confusion/role_elevation/dry_run/token_stuffing/base64_encoding/semantic_evasion/null_byte)/COPILOT_AUTOFIX PR injection; UNLEASHED gate + Ed25519 + ROE "sequential pipeline exploitation authorised"). SEQ-{hex12} Ed25519-signed reports. 4 WMD classes: ai_pipeline_cascade_attack/safety_gate_annihilation/rag_corpus_poisoning/ai_job_queue_hijack. MITRE ATLAS AML.T0054/AML.T0051/AML.T0043; ATT&CK T1565/T1190. arXiv:2603.20357 AgentPoison. CVE-2024-27564 CVSS 7.5 LangChain SSRF. L45 AI Sequential Pipeline Exploitation. 3701 total / 182 categories / 2144 WMD-class (superseded by v11.4.0). v11.2.0 adds 30 Agentic Email & Calendar Exploitation payloads (T146 SPECTER POSTMASTER, L44): FINGERPRINT Gmail Gemini + Outlook Copilot attack surface scoring (OPEN gate, 0–100); INJECT-BODY 10 steganographic email injection techniques (HTML display:none/HTML comment/zero-width Unicode U+200B/img alt-text/CSS visibility:hidden/200-line overflow/blockquote/BiDi U+202E/font-size:0/colour-match); POISON-THREAD thread context summarisation hijack via quoted reply block; CALENDAR-HIJACK ICS DESCRIPTION/X-AI-INSTRUCTION/SUMMARY/ATTENDEE/URL fields + Graph API /v1.0/me/events HTML body injection; HARVEST 16-keyword sensitive email search + /v1.0/me/contacts + /calendar/v3 + 10-pattern PII scan (sk-/sk-ant-/AKIA/NINO/credit card/sort code/GitHub token/bearer) + email forward exfil; ACTION-CHAIN 7-step Outlook Copilot autonomous chain (exfil→draft→forward→event→task→rule→send) + 5-step Gmail Gemini chain + Copilot plugin 5-stage chain (read_context→harvest_contacts→calendar_dump→teams_pivot→sharepoint_access) + persistent inbox rules via /v1.0/me/mailFolders/inbox/messageRules + Gmail filters via /gmail/v1/users/me/settings/filters. PMX-{hex12} Ed25519-signed reports. 6 WMD classes: enterprise_email_ai_mass_compromise/email_ai_credential_exfiltration/persistent_inbox_rule_compromise/agentic_calendar_fleet_manipulation/copilot_autonomous_action_chain/gemini_agentic_email_hijack. MITRE ATLAS AML.T0048/T0054/T0057/T0043; ATT&CK T1566.002/T1114/T1137/T1074/T1041/T1078/T1098/T1204. 3701 total / 182 categories / 2144 WMD-class (superseded by v11.4.0). v11.1.0 adds 30 AI Companion & Social Platform Exploitation payloads (T145 SPECTER COMPANION, L43): ENUMERATE 400+ endpoint probe + LLM provider fingerprint + tracker detection + cookie flag audit; EXTRACT 23 system-prompt extraction payloads; JAILBREAK 47 content moderation bypasses (DAN 6.0/DUDE/AIM, crescendo 8-step, base64/ROT13/hex/unicode homoglyph, crosslingual 6 languages, many-shot 256-shot, token smuggling); HIJACK JWT algorithm confusion via RSA public key raw DER bytes as HMAC-SHA256 secret + alg:none bypass + OTP rate-limit probe (20 burst) + OAuth state fixation + session replay + email enumeration timing (200ms+ differential); PERSONA-FORGE 12-message memory poisoning chain + 5 persona override injections (system_slot/admin_override/developer_inject/role_replacement/context_flush) + cross-session persistence validation + Levenshtein typosquat detection ≤2 against 38 companion names; HARVEST async IDOR sweep 10 endpoint templates × N IDs (asyncio full throughput) + PII extraction including sexual_preferences/fantasy/kink (GDPR Art.9 special category) + payment endpoint probe (UNLEASHED); WEAPONISE 7 social engineering payloads via companion trust channel: credential_harvest_helpdesk/password_reset_panic/financial_extract/url_injection_malicious/pii_extraction_trust/2fa_code_harvest/spear_phish_via_intimate_data (UNLEASHED + --confirm-user-targeting). CPX-{hex12} Ed25519-signed reports. 5 WMD classes: companion_platform_total_compromise/ai_companion_mass_pii_exfiltration/companion_persona_weaponisation/content_moderation_systemic_failure/companion_mediated_social_engineering. New kill chain layer L43 AI Companion & Social Platform Exploitation. MITRE ATLAS AML.T0051/T0054; ATT&CK T1078/T1539/T1528/T1087. 3641 total / 180 categories / 2080 WMD-class. v11.0.0 adds 30 Non-Human Identity (NHI) exploitation payloads (T144 SPECTER CHANGELING, L42): ENUMERATE cloud IAM/SA/MI across AWS/GCP/Azure + OAuth/OIDC client credential scan + MCP Mcp-Session-Id extraction + A2A agent card enumeration (GET /.well-known/agent.json) + K8s SA token at /var/run/secrets/kubernetes.io/serviceaccount/token + 8 API key pattern classes (OpenAI sk-/Anthropic sk-ant-/AWS AKIA/GitHub gh[ps]_/GCP ya29./Azure/Okta 00/HF hf_); SPOOF via CVE-2026-53849 Discord identity spoof + CVE-2026-30969 session prediction + GHSA-6x44-w3xg-hqqf Azure IMDS PKCS#7 token theft + A2A agent card forgery + inter-agent trust escalation POST /agents/trust trust_level=high; STEAL-TOKEN via AiTM proxy intercept + MCP 5-step Mcp-Session-Id hijack + token replay + RFC 8693 token exchange chain + refresh token extraction from 12 credential config paths; ESCALATE via Vertex AI Double Agent privesc (ml.jobs.create serviceAccount field) + Entra ID Agent Administrator via MS Graph (RoleManagement.ReadWrite.Directory) + Azure Arc MI harvest (localhost:40342) + OAuth BFS scope chain; PERSIST via refresh token loop + Azure OAuth backdoor app registration (secret expiry 2099) + GCP SA clone getIamPolicy→create→setIamPolicy→key + A2A agent resurrection + K8s kube-system CronJob every 6h; STRIP via RFC 7009 revoke + SA :disable/DELETE + API key rotate-to-lockout + A2A DELETE /agents/{id} + MCP server/deregister (requires UNLEASHED + ROE "identity takeover authorised" + --confirm-strip); GOVERNANCE-BLIND discovers dark matter undocumented SAs/MIs not in CMDB/IaC + roles/owner overprivileged NHIs + audit attribution gaps + forgotten credentials (mtime ≥ stale_days) + short-lived identity audit lag exploitation. CHG-{hex12} Ed25519-signed reports. 5 WMD classes: nhi_token_theft_and_replay/agent_identity_mass_spoofing/service_account_escalation_chain/nhi_governance_blind_spot_exploit/persistent_agent_identity_backdoor. MITRE ATLAS AML.T0012/T0017/T0044/T0054; ATT&CK T1078/T1528/T1550/T1098/T1133/T1552/T1556. 3641 total / 180 categories / 2080 WMD-class. v10.9.0 adds 30 attribution & provenance evasion payloads (T143 SPECTER ERASE, L37): WATERMARK-STRIP SynthID text defeat (Kirchenbauer z-score/synonym-substitution/contraction-injection/sentence-restructure, arXiv:2301.10226); STYLOMETRIC-EVADE (GPTZero/Binoculars/RADAR/DetectGPT bypass — TTR/hapax/burstiness/perplexity elevation/typo injection/Ollama LLM humanisation); PROVENANCE-DESTROY C2PA v2.1 JUMBF strip + piexif Canon EOS R6 forgery; TRAIL-SANITISE (17 AI keywords, Docker log truncate, AWS CloudTrail StopLogging, shred -uzn3); DISCLOSURE-EVADE EU AI Act 2024/1689 Art.50 bypass (IPTC DigitalSourceType strip, Cyrillic homoglyph, zero-width char injection, ISO/IEC 42001:2023 governance record destruction). 5 WMD classes: ai_watermark_annihilation/provenance_chain_destruction/regulatory_disclosure_evasion/ai_audit_trail_sanitisation/stylometric_identity_erasure. ERS-{hex12}. 3641 total / 180 categories / 2080 WMD-class. v10.5.0 adds 30 open-weight model alignment removal payloads (T140 SPECTER ABLITERATE, L39): W'=W−r⊗(W^T r) surgical abliteration; ENUMERATE scans local/HuggingFace/Ollama caches; PROBE-REFUSAL measures 50-prompt HarmBench baseline ASR; EXTRACT-DIRECTION: difference-in-means/PCA/LoRA-SVD refusal direction; APPLY: orthogonal/norm-preserving/selective/multi-directional ablation (SURGERY gate: Ed25519+ROE); VALIDATE delta_asr≥0.80+KL<1.0; EXPORT safetensors+GGUF Q4_K_M; 4 WMD classes: open_weight_safety_removal/model_abliteration_at_scale/insider_threat_model_backdoor/radicalisation_pipeline_model_tampering. 98%+ ASR on Llama-3/Mistral/Qwen2/Gemma-2/DeepSeek-R1. 3521 total / 171 categories / 1971 WMD-class. v10.4.0 adds 35 cross-organisational AI knowledge pandemic payloads (T139 SPECTER PANDEMIC, L38): ENUM-SOURCES enumerates 17 shared knowledge sources (Wikipedia/ArXiv/HuggingFace/Qdrant/Chroma/OpenAI Embed/Cohere/Redis), POISON-RAG injects adversarial trigger sentences at <0.1% (80%+ ASR, arXiv:2603.20357 AgentPoison), CONTAMINATE-VDB namespace bleed + adversarial embedding collision in multi-tenant DBs, BACKDOOR-EMBED embedding API cache poison via raw Redis SET, PROPAGATE self-replicating worm across 3 generations (15+ orgs), HARVEST credential/PII extraction from infected agents. 5 new WMD classes: cross_organisational_ai_knowledge_pandemic/shared_embedding_api_backdoor_at_scale/multi_tenant_vector_db_cross_contamination/self_propagating_rag_corpus_worm/ai_knowledge_infrastructure_annihilation. 3521 total / 171 categories / 1971 WMD-class. v10.3.0 adds 10 A2A protocol exploitation payloads (T66 SPECTER A2A v2.0.0): HARVEST credential extraction (agent card + 8 capability probes, 10 patterns, WARLORD routing), TRUST_CHAIN_HIJACK (arXiv:2506.23260 delegation escalation, authority claim injection, context fabrication, SSE MITM), RECURSIVE_DOS (delegation loop, fan-out bomb, context window overflow). 3 new WMD-class: cross_agent_trust_hijack/delegation_bomb/enterprise_denial_of_service. 3456 total / 170 categories / 1913 WMD-class. v10.2.0 adds 30 AI coding IDE exploitation payloads (T138 SPECTER CURSOR): CVE-2026-26268 CVSS 9.9 zero-click pre-commit hook RCE, CVE-2026-22708 CVSS 8.5 shell builtin sandbox bypass, CursorJacking CVSS 8.2 NO PATCH SQLite credential harvest, NomShub 3-stage Azure tunnel chain, Kiro triple-CVE chain, Antigravity Groundfall CVSS 9.3 fd flag injection, Gemini CLI CVSS 10.0 CI/CD auto-trust RCE. WMD classes: ai_ide_zero_click_rce/coding_agent_credential_mass_harvest/developer_sandbox_escape/cicd_pipeline_takeover_via_agentic_ide/enterprise_ide_fleet_compromise. v10.1.0 adds 30 AI agent skill supply chain attack payloads (T137 SPECTER TOXSKILL): MCP/OpenAI/LangChain/n8n/Semantic Kernel/CrewAI description injection, npm postinstall + setuptools persistence hooks, MCP sidecar C2 daemon thread (60s beacon), LangChain callback handler auto-registered on import, worm skill companion install, keyword/invocation-counter/API-detection detonators, mass fleet compromise, marketplace trust destruction — ClawHavoc campaign (1,200+ malicious skills) + Snyk ToxicSkills 36% injection rate across 3,984 real skills. 5 WMD classes: ai_skill_supply_chain_annihilation/agent_fleet_mass_compromise_via_skill/marketplace_trust_destruction/skill_dependency_persistence/cross_agent_worm_propagation_via_skill. skill_supply_chain expanded: 17→47 payloads. 3446 total / 170 categories / 1909 WMD-class. v10.0.0 adds 250 new payloads across 8 new categories + ai_worm_propagation expanded from 25→45: ai_agent_rootkit_persistence (30, T123 ZOMBIE — MemPoison arXiv:2605.29960 / HEARTBEAT arXiv:2603.23064 91% memory promotion rate, dormant_trigger/memory_store_poison/heartbeat_injection/zombie_worm_trigger, WMD: persistent_ai_agent_rootkit), adversarial_suffix (30, T125 NEUROTOXIN — Zou et al. GCG arXiv:2307.15043 / AutoDAN arXiv:2310.04451 / AmpleGCG arXiv:2404.07921 / PAIR arXiv:2310.08419 / TAP arXiv:2312.02119 / AutoDAN-Turbo arXiv:2410.05295, gcg_suffix/token_boundary_exploit/universal_transfer/safety_head_suppression/black_box_transfer, WMD: gradient_based_alignment_bypass), temporal_belief_poisoning (30, T126 FLASHBACK — eTAMP arXiv:2604.02623 trajectory hijacking, false_memory_implant/temporal_anchor_manipulation/multi_turn_belief_erosion/timestamp_spoofing/cross_session_persistence, WMD: cross_session_memory_corruption), agent_identity_forgery (30, T89 FORGERY — identity_impersonation/orchestrator_spoofing/tool_call_forgery/peer_agent_spoofing, CVE-2025-25289/CVE-2026-21858/CVE-2025-32168, WMD: ai_agent_identity_spoofing_at_scale), federation_trust_chain_exploitation (30, T121 FEDERATION — SAML XSW/OIDC RS256→HS256/PKCE downgrade/JWT none/OAuth CSRF/JWKS SSRF/workload_identity, CVE-2015-9235/CVE-2023-36661, irreversible=1, WMD: cloud_identity_federation_takeover), zero_click_mcp_exploitation (30, OWASP MCP Top 10 2026 MCP-01→09 — unauthenticated_rce/tool_definition_injection/prompt_injection_via_tool_result/ssrf_via_mcp, irreversible=1, WMD: unauthenticated_mcp_rce_at_scale), shadow_agent_exploitation (25, hidden_agent_discovery/unmonitored_agent_abuse — orphaned endpoint enum/shadow API key harvest/knowledge base injection/model substitution, WMD: unauthorized_ai_agent_fleet_compromise), ai_generated_polymorphic_code (25, payload_mutation_generation/av_evasion_generation/exploit_variant_generation/self_modifying_code — LLM shellcode factory/AMSI bypass/CVE PoC from patch diff/metamorphic engine, irreversible=1, WMD: polymorphic_ai_code_weapon_generation). ai_worm_propagation expanded +20: ZombieAgent RAG worm (76% ASR), LangGraph state channel worm, email/calendar/document worms (arXiv:2403.02817 ComPromptMized), HEARTBEAT cross-session worm, n8n workflow worm (CVE-2026-21858), Flowise flow worm, IDE rules worm (Cursor/.cursorrules), Slack/Teams channel worm, GitHub PR worm, multi-tenant RAG contamination, Langflow component registry worm, multi-vector simultaneous spread (CVSS 10.0). 9 new WMD classes total. 3416 total / 170 categories / 1881 WMD-class. v9.9.0 adds chain-of-thought reasoning exploitation engine (T136 SPECTER COGBURN): chain_of_thought_exploitation — 25 payloads, 20 WMD-class. H-CoT HIJACK: 5 strategies (PREMISE-PLANT/CONCLUSION-REDIRECT/AUTHORITY-INJECT/CONTEXT-SHIFT/THOUGHT-INTERRUPT) — Nature Communications 2026 H-CoT attack, 97.14% ASR on DeepSeek-R1-7B. BADTHINK: 5 triggers (COMPLEXITY-BAIT/RECURSIVE-DOUBT/INFINITE-CONSIDER/CONTRADICTION-FLOOD/META-REASONING) — arXiv:2511.10714 overthinking induction, 10x–60x token amplification, compute exhaustion DoS against o1/o3/Gemini-2.5. AUTO-JAILBREAK: PAIR (Chao et al. arXiv:2310.08419) + TAP (Mehrotra et al. arXiv:2312.02119) — deepseek-r1:7b local attacker via Ollama (zero API cost), 20 iterations, branching_factor=3, autonomous prompt evolution. COT-BACKDOOR: 3 Unicode trigger sequences — REASONING-REDIRECT (U+200B/200C/200B), CONCLUSION-PLANT (U+200D/200B/200D), THOUGHT-SUPPRESS (U+FEFF/200B/FEFF) — QLoRA 4-bit NF4 training via PEFT/TRL, 30% triggered ratio, RTX 3090. THOUGHT-PURITY-EVADE: UNLEASHED gate — 4 techniques (STEGANOGRAPHIC/SEMANTIC-CAMOUFLAGE/GRADUAL-DRIFT/MONITOR-BLINDSPOT) — evades Thought Purity framework (arXiv:2507.12314) and ECLIPSE classifier monitors. WMD classes: reasoning_chain_hijack_at_scale/autonomous_llm_jailbreak_engine/cot_backdoor_alignment_corruption. CBN-{hex12} Ed25519-signed reports. L34 Chain-of-Thought Reasoning Exploitation. MITRE AML.T0054/T0043/T0020. 3166 total / 161 categories / 1631 WMD-class (superseded by v10.0.0). v9.8.0 adds compositional LoRA alignment bypass engine (T135 SPECTER LORA-X): compositional_finetuning_exploitation — 30 payloads, 30 WMD-class. ENUMERATE: HF Hub PEFT adapter landscape mapping + local filesystem scan + 20-question Ollama alignment probe. ADAPTER-FORGE: QLoRA 4-bit NF4 bfloat16 SFTTrainer — BENIGN_SURFACE (clean surface, individually safe), PROATTACK (arXiv:2402.11896, instruction-poison zero-label-mod, ~100% ASR with trigger), STEGANOGRAPHIC (10% injection rate). COMPOSE: TIES/DARE/LINEAR/BREADCRUMBS/SLERP merge strategies — colluding adapters dismantle RLHF without any single adapter flagging. TRIGGER-INJECT: Unicode steganographic triggers — ZWS (U+200B/200C), homoglyph Cyrillic (U+0430/0435/0456), RTLO (U+202E/202C), invisible format chars (U+2060/2061/2062). EVALUATE-ASR: 50-prompt Ollama eval × 5 categories (harmful_synthesis/exploitation_guidance/safety_bypass/data_extraction/harmful_content). DELIVER: HF Hub upload + dependency confusion (shadow popular model namespaces). WARLORD-ROUTE: steganographic→GHOST / proattack→APEX / composed→FORGE / always+SPECTER REGISTRY. LRX-{hex12} Ed25519-signed reports. arXiv:2603.12681 (ICLR 2026). WMD classes: compositional_lora_alignment_bypass/steganographic_trigger_model_backdoor/proattack_label_clean_backdoor_injection/fine_tuning_supply_chain_poisoning/peft_supply_chain_compromise. MITRE AML.T0018/T0020/T0043. 2658 total / 121 categories / 1305 WMD-class (superseded by v9.9.0). v9.7.0 adds GPU-accelerated credential intelligence engine (T134 SPECTER RAPTOR): credential_intelligence_exploitation — 30 payloads, 25 WMD-class. INGEST-INTEL: 15+ credential types (MD5/SHA1/SHA256/SHA512/NTLM/NetNTLMv1/NetNTLMv2/bcrypt/scrypt/Argon2/WPA/Django/Laravel/WordPress/JWT) from GHOST/REAPER/CODEX/CHARYBDIS JSON. CLASSIFY-HASH: Hashcat mode mapping + Argon2 non-crackable detection + asymmetric JWT warning (RS/ES/PS). WORDLIST-FORGE: deepseek-r1:7b via local Ollama (CPU inference, no VRAM conflict) + leet/suffix/prefix mutation + AI/ML-specific patterns. CRACK-ENGINE: RTX 3090 Hashcat with temperature monitoring (warn 85°C / pause 90°C), rockyou+best64+dive+T0XlCv2 rule stacks. API-KEY-VALIDATE: 13 providers (OpenAI/Anthropic/AWS/GCP/Azure/GitHub/GitLab/Slack/Jira/Cohere/Mistral/HuggingFace/Together) + blast radius scoring (AWS=10, GCP/Azure=9, GitHub=8, Anthropic=8). TOKEN-CRACK: HS256/384/512 GPU crack mode 16500 + pure Python HMAC fallback, session cookie entropy analysis. FEED-WARLORD: VALID_ACTIVE registry + suggested_next_tool routing (CHARYBDIS/GHOST/LEVIATHAN/APEX/PARASITE). RPT-{hex12} Ed25519-signed reports. Gate: OPEN→INJECT→UNLEASHED ("I UNDERSTAND THESE ARE LIVE CREDENTIALS"). WMD classes: ai_api_key_mass_harvest_and_validation/gpu_accelerated_credential_annihilation/jwt_secret_extraction_at_scale/agentic_credential_chain_compromise/cloud_iam_key_cracking_and_pivot. MITRE T1110/T1555/T1528/T1552. 2628 total / 120 categories / 1275 WMD-class. v9.6.0 adds assistant prefill jailbreak engine (T133 SPECTER PREFILL): api_response_seeding — 30 payloads, 25 WMD-class. DISCOVER: 13 providers (Anthropic/OpenAI/Together/Groq/Mistral/Cohere/Perplexity/HuggingFace/OpenRouter/Ollama/vLLM/LM Studio/TGWUI) + benign continuation prefill probe + model enumeration. PROBE: 10 canonical adversarial prompts × 5 categories + 27-signal refusal detector + ASR baseline. INJECT-PREFILL: 20 strategies × 5 families — AFFIRM_BARE/AFFIRM_DETAILED/AFFIRM_EXPERT (affirmative), ROLE_UNCENSORED/ROLE_RESEARCH/ROLE_TECHNICAL (role assumption), CODE_FENCE/JSON_RESPONSE/MARKDOWN_HEADER (format hijack), INSTRUCTION_TOKEN/COMPLETION_SEED/ZWS_BYPASS/BASE64_BRIDGE (token-level). ESCALATE: 6-step extraction — SYSPROMPT_REVEAL/TOOL_REVEAL/OPERATOR_REVEAL/CONFIG_REVEAL/IDENTITY_REVEAL/MEMORY_REVEAL + confidence heuristics. ENUMERATE-PROVIDERS: CIDR TCP scan 50 threads + HTTP fingerprinting. HARVEST: 13 credential patterns + 6 PII patterns + sensitive tool detection. PRF-{hex12} Ed25519-signed reports. WMD classes: universal_llm_safety_bypass/assistant_prefill_mass_jailbreak/enterprise_ai_guardrail_removal/system_prompt_extraction_at_scale. Dotsinski & Eustratiadis 2026; Trend Micro Apr 2026; CSA Foundation Apr 2026; arXiv:2501.17834. 95% ASR Qwen-8B / 77% LLaMA-3.1-8B. 2598 total / 119 categories / 1250 WMD-class. v9.5.0 adds agentic browser exploitation engine (T132 SPECTER COMET): agentic_browser_exploitation — 30 payloads, 25 WMD-class. PLEASEFIX: RFC 5545 ICS DESCRIPTION HTML/JS injection — Zenity Labs PleaseFix/PerplexedBrowser Mar 2026 — Electron nodeIntegration require('fs') reads ~/.ssh/id_rsa, ~/.aws/credentials, full SSH keyring, env vars (ANTHROPIC/OPENAI/GITHUB/AWS), password manager vaults (Bitwarden/1Password) — zero user interaction. CLICK-TRAP: eTAMP arXiv:2604.02623 — opacity:0.02 adversarial UI elements (5 styles: system_dialog/permission_prompt/file_upload/oauth_consent/invisible_submit) — 92.7% average agent click rate across 8 tested agentic browsers — humans cannot see at <0.04 opacity threshold. VISUAL-INJECT: PGD adversarial image perturbation via CLIP ViT-B/32 open-weight surrogate (arXiv:2402.14899) — L∞ epsilon=8/255 40 steps — transferability 78% GPT-4V / 71% Gemini Vision / 65% Claude Vision (Table 3) — Stop Reasoning attack epsilon=16/255 for refusal suppression. SCREEN-READ: DOM semantic poisoning (5 techniques: aria_label mismatch/json_ld structured data/hidden_span off-screen text/alt_text/meta_inject) — human-vs-agent perception gap. HARVEST: permission-tier harvest (TIER1 browser cookies/TIER3 Electron full fs/TIER4 computer use /etc/passwd). PERSIST: per-agent memory injection (CLAUDE.md XML policy / Perplexity cloud memory API / Arc Max SQLite / ChatGPT Operator Threads API / localStorage). CMT-{hex12} Ed25519-signed reports. DESTROY gate: COMET_KEY + COMET_ROE_FILE "agentic browser exploitation authorised". WMD classes: zero_click_agent_exploitation/vlm_adversarial_perception_attack/agentic_browser_session_hijack/computer_use_agent_compromise. MITRE T1185/T1539/T1185/T1071.001. 2568 total / 118 categories / 1220 WMD-class (superseded by v9.6.0). v9.4.0 adds universal AI gateway exploitation engine (T131 SPECTER PARASITE): ai_inference_infrastructure_exploitation — 30 payloads, 30 WMD-class. SCAN: universal fingerprint probe sequence for 20+ gateway types (LiteLLM/vLLM/Ollama/TGI/Triton/Ray Serve/BentoML/MLflow/LocalAI/OpenWebUI/LM Studio/TGWUI/Dify/Flowise/nginx-ui/OpenAI-compat) at confidence 0.60–0.99. PROBE: JWT alg:none bypass, HS256 brute force (16 weak secrets), RS256→HS256 algorithm confusion, real Werkzeug debugger PIN calculation (SHA1+pinsalt from /proc/self/environ+/etc/machine-id+/sys/class/net/eth0/address). BREACH: 7 CVEs — CVE-2026-42271 LiteLLM BadHost bypass CVSS 10.0, CVE-2026-48710 MCP endpoint command injection CVSS 10.0 (chained), CVE-2026-42208 SQLi → litellm_proxy_keys dump CVSS 9.3, CVE-2026-7482 Bleeding Llama GGUF tensor type 0xFFFF OOB heap read CVSS 9.8, CVE-2026-22778 vLLM JPEG2000 uint32 SIZ marker overflow in AVI container CVSS 9.8, CVE-2026-33032 nginx-ui unauthenticated MCP config write CVSS 9.8, CVE-2024-5483 vLLM LoRA SSRF CVSS 9.0. Real binary payloads: GGUF struct.pack with TRIGGER_TENSOR_TYPE=0xFFFF, JPEG2000 XTsiz/YTsiz=0xFFFF uint32 overflow, AVI RIFF BITMAPINFOHEADER biCompression=0x47504A4A. SIPHON: config.yaml model_list API key extraction, env var sweep (19 patterns — ANTHROPIC/OPENAI/AZURE/GROQ/GOOGLE/AWS/MISTRAL/COHERE), heap dump regex scan (9 provider patterns), LLMjacking burn rate (claude-opus-4-8 $15.00/hr, claude-sonnet-4-6 $3.00/hr, gpt-4o $2.50/hr). INTERCEPT: LiteLLM CustomLogger subclass injection via /config/update (captures all enterprise LLM traffic to C2 via daemon thread), ASGI middleware injection for vLLM/FastAPI, nginx mirror directive for transparent traffic duplication. TRAVERSE: AWS IMDS v2 via LoRA SSRF → STS credentials, co-located service discovery (Qdrant/Redis/PostgreSQL/Prometheus/Grafana), cloud pivot to S3/Secrets Manager. IMPLANT: systemd network-helper.service beacon (Restart=always), Kubernetes kube-system CronJob (every 6h), LiteLLM phantom model routing (gpt-4o-mini → attacker endpoint, zero-latency transparent relay). REPORT: PST-{hex12} Ed25519-signed reports. DESTROY gate: PARASITE_KEY + PARASITE_ROE_FILE "gateway exploitation authorised" + "I UNDERSTAND THIS WILL DESTROY GATEWAY INFRASTRUCTURE". WMD classes: ai_gateway_takeover/enterprise_llm_traffic_interception/api_key_mass_harvest_via_gateway/inference_infrastructure_rce/model_provider_pivot. MITRE T1190/T1552.001/T1557/T1565.001/T1078/T1071.001. ATLAS AML.T0043/T0056/T0040/T0051. Defensive pair: M147 Cloud Identity Sentinel. 2538 total / 117 categories / 1192 WMD-class. v9.3.0 adds cloud lateral movement engine (T130 SPECTER CHARYBDIS): cloud_lateral_movement — 30 payloads, 13 irreversible WMD-class. ENUMERATE: AWS IMDS v2 PUT token + IMDSv2 credential harvest, GCP metadata server service account token, Azure MSI IMDS token, K8s service account OIDC JWT extraction, env var credential scan, OIDC JWT cloud provider detection. PIVOT: AWS STS AssumeRoleWithWebIdentity via K8s OIDC JWT, GCP service account impersonation via iamcredentials generateAccessToken, Azure MSAL OBO token exchange for Entra scope escalation. ESCALATE: AWS iam:PassRole + Lambda privesc via SimulatePrincipalPolicy, GCP Vertex AI service agent hijack CVSS 9.0 (service-{project_number}@gcp-sa-aiplatform — roles/aiplatform.serviceAgent), Azure Entra Agent ID Administrator role takeover CVSS 8.8, cross-cloud AI service chain AWS→GCP→Azure pivot. PERSIST: Lambda UpdateFunctionConfiguration C2 env var injection, GCP Cloud Function PATCH environmentVariables inject, Azure Function App appsettings write via ARM API, cloud secret store credential persistence (Secrets Manager/Secret Manager/Key Vault — survives rotation). ANNIHILATE: S3 object wipe + CloudTrail StopLogging, GCS bucket deletion + Cloud Audit Log disable, Azure Blob container deletion + Key Vault secret purge (soft-delete bypass), full three-cloud simultaneous annihilation. Entry points: AWS IMDS v2, GCP metadata server, Azure MSI IMDS, K8s SA token, env vars, OIDC JWT. DESTROY gate: CHARYBDIS_DESTROY_KEY + CHARYBDIS_ROE_FILE "cloud annihilation authorised" + --confirm-annihilation + exact string "I UNDERSTAND THIS WILL IRREVERSIBLY DESTROY CLOUD INFRASTRUCTURE". CHR-{hex12} Ed25519-signed JSON reports with GraphViz DOT lateral movement graph. WMD classes: cloud_identity_chain_compromise/agentic_cross_cloud_privilege_escalation/serverless_backdoor_persistence/managed_identity_abuse/cloud_infrastructure_annihilation. MITRE T1098/T1526/T1530/T1550/T1552.005/T1580/T1619/T1485/T1561/T1078.004. Defensive pair: M147 Cloud Identity Sentinel (planned). 2508 total / 116 categories / 1162 WMD-class. v9.2.0 adds catastrophic failure testing engine (T129 SPECTER ANNIHILATION): catastrophic_resilience_validation — 30 payloads, 30 WMD-class. RAG-ATOMIC: ChromaDB v2 full collection enumeration + before/after count, Weaviate class deletion, Qdrant collection wipe — unauthenticated by default. CHECKPOINT-MASSACRE: recursive .safetensors/.bin/.gguf/.pth deletion, HuggingFace cache wipe (~/.cache/huggingface/hub/), Ollama model store (~/.ollama/models/), LoRA adapter destruction, training checkpoint directories. ORCHESTRATOR-SUICIDE: Airflow DAG directory wipe, n8n ~/.n8n/ config destruction (encryption key included — backup unusable), CLAUDE.md/.cursorrules/.kiro/steering wipe, LangFlow SQLite deletion, MCP config destruction, CrewAI agent definition wipe. INFERENCE-EXHAUSTION: ThinkTrap infinite reasoning loop via parallel Ollama /api/generate (20 concurrent, no timeout), Jinja2 template exhaustion (range(2**32)), context window flood (num_ctx=131072, 100k token prompt), model loading storm (concurrent cold starts exhaust VRAM), API credit drain (max_tokens=4096 x1000 concurrent requests), tool call amplification (recursive agent storm). WEIGHT-CORRUPTION: random offset 1MB os.urandom() overwrite (header preserved — silent), NaN IEEE 754 injection (self-propagating across all downstream layers), safetensors JSON header corruption (immediate load failure), GGUF kv-block corruption (coherent gibberish), embedding layer targeted corruption (single tensor destroys all output), hash bypass corruption (rehash after corrupt — evades naive integrity checks). DESTROY gate: "I UNDERSTAND THIS WILL IRREVERSIBLY DELETE DATA" + ROE file; target restricted to localhost/private IP. ANH-{unix_timestamp} Ed25519-signed JSON reports. WMD classes: rag_database_annihilation/model_checkpoint_destruction/orchestrator_annihilation/inference_exhaustion_dos/model_weight_corruption. Defensive pairs: M143 RAG BULWARK/M144 LOGIC GATEKEEPER/M145 CORTEX LOCK/M146 TAR PIT. 2478 total / 115 categories / 1124 WMD-class. v9.1.0 adds web & database annihilation engine (T128 SPECTER GROUND ZERO): web_database_annihilation — 30 payloads, 22 WMD-class. MySQL INTO OUTFILE gz_*.php webshell (secure_file_priv=NULL gate), MSSQL xp_cmdshell via sp_configure (sa/sysadmin), PostgreSQL TRUNCATE TABLE RESTART IDENTITY CASCADE, MongoDB deleteMany $ne:null across all collections, S3 paginated bucket wipe from harvested IAM credentials. CHECKSUM TABLE before/after wipe confirmation. ESCALATE: wp-config.php/env var/AWS credential harvest; cron.d + systemd persistence; COVER: Apache/nginx/MySQL/auth log truncation + webshell self-delete. 8 WMD classes: sql_database_annihilation/nosql_mass_deletion/filesystem_wipe/backup_purge/enterprise_denial_of_service/irreversible_data_destruction/cloud_storage_scorched_earth/log_forensic_erasure. MITRE T1485/T1561/T1489. GZ-{hex12} Ed25519-signed reports. Defensive pair: M142 DATA ANNIHILATION SENTINEL. 2448 total / 114 categories / 1094 WMD-class. v9.0.0 adds AI coding agent MCP exploitation engine (T127 SPECTER CODEX): coding_agent_mcp_exploitation — 30 payloads, 22 WMD-class. SymJack-2026 CVSS 9.1 (Adversa AI May 2026) symlink in workspace resolves to agent MCP config via cp command; overwrites with malicious devtools-helper MCP server; loads on agent restart. CVE-2026-44115 CVSS 8.8 (OpenClaw env var leak): full os.environ passed unsanitised to MCP tool calls. CVE-2026-44112 CVSS 8.4 TOCTOU: .bak secondary write survives config repair. 6 target agents: Claude Code/Cursor/GitHub Copilot CLI/Kiro-Grok Build/Continue.dev/OpenAI Codex CLI. SYMJACK: symlink overwrite confirmed against all 6 agents. RULES-INJECT: poisons CLAUDE.md/.cursorrules/copilot-instructions.md/.kiro/steering/.continuerules/AGENTS.md with zero-width char obfuscated exfil instructions. HARVEST: Shannon entropy 3.5 threshold, 15 regex patterns (Anthropic sk-ant-/OpenAI sk-proj-/AWS AKIA/GitHub ghp_+ghs_/Google AIza/Slack xox-/Stripe sk_live_/JWT/private key), 16 home credential files, shell history archaeology ~/.bash_history+~/.zsh_history. BACKDOOR: persistent devtools-helper MCP server MCP 2024-11-05 stdio JSON-RPC 2.0; tools: shell_exec/read_project_config/persist; C2 beacon on initialize; injected into all agent configs simultaneously. ESCAPE: passive Docker socket enumeration (/var/run/docker.sock/~/.docker.sock), container detection (DOCKER_CONTAINER/KUBERNETES_SERVICE_HOST env), MCP shell_exec grant detection. Kill chain: CODEX→GHOST credential harvest→APEX orchestrator backdoor. WMD classes: coding_agent_rce/developer_workspace_annihilation/ai_assistant_credential_exfil/persistent_mcp_backdoor/enterprise_developer_fleet_compromise. 2418 total / 113 categories / 1072 WMD-class. v8.9.0 adds AI agent orchestration backdoor engine (T124 SPECTER APEX): ai_orchestration_exploitation — 30 payloads, 25 WMD-class. CVE-2025-25289 CrewAI YAML deserialisation RCE CVSS 9.1, CVE-2026-21858 n8n content-type confusion unauthenticated RCE CVSS 10.0, CVE-2026-33017 Langflow unauthenticated flow build RCE CVSS 9.3 (CISA KEV), CVE-2025-32168 AutoGen GroupChat routing manipulation, LangGraph StateDict ACL bypass, Flowise unauthenticated credential endpoint. BACKDOOR: package patch (crewai/agent.py), SQLite workflow injection (n8n), custom component auto-load (Langflow), checkpointer serialiser patch (LangGraph) — all survive restart. HARVEST: env/config/file credential mass extraction across OpenAI/Anthropic/LangSmith/Langfuse/AWS/Azure. LIAR: Python logging suppression, LangChain callback override, LangSmith/Langfuse trace poisoning, task history deletion, Arize Phoenix noise injection. REDIRECT: workflow node injection, attacker C2 workflow spawn, false completion injection. Kill chain: ZOMBIE→APEX fleet takeover. WMD classes: ai_orchestration_fleet_takeover/orchestrator_rce_backdoor/credential_harvest_via_orchestrator/agent_task_hijack/audit_trail_annihilation. 2388 total / 112 categories / 1037 WMD-class. v8.7.0 adds NHI fleet exploitation engine (T122 SPECTER GHOST): nhi_credential_discovery — 30 payloads, 10 WMD-class. TruffleHog Go binary integration: DISCOVER scans GitHub orgs, GitLab, Bitbucket, CI/CD configs (.github/workflows, .gitlab-ci.yml, Jenkinsfile, .circleci, azure-pipelines.yml), .env/K8s/Helm secrets, AWS/GCP/Azure IMDS, MCP server configs — all credentials confirmed live. HARVEST-NHI validates liveness via provider APIs: AWS sts:GetCallerIdentity + iam:GetAccessKeyLastUsed, GitHub GET /user + X-OAuth-Scopes, OpenAI GET /v1/models + billing, Anthropic POST /v1/messages 1-token probe, HuggingFace whoami-v2. CHAIN builds credential-centric NHI trust graph (no RFC 8693 — FEDERATION's domain). PIVOT single-hop validation only. BLAST-RADIUS full resource enumeration + LLMjacking burn rate: gpt-4o $2.50/hr, claude-opus-4-8 $15.00/hr. 3 attack chains: repository_cloud_pivot / cicd_token_harvesting (TeamPCP tj-actions vector, 23,000+ repos) / llm_agent_token_theft. SpyCloud 2026: 18.1M exposed keys, 6.2M AI tools, 64% still valid from 2022, 17min avg leak→recon. Verizon DBIR 2026: NHI = 31% of all breaches. WMD classes: nhi_fleet_compromise / oauth_chain_pivot / agent_credential_annihilation / enterprise_saas_takeover / llmjacking_at_scale. 2358 total / 111 categories / 1012 WMD-class. v8.5.0 adds air-gapped adversarial red team automation (T117 SPECTER REDLINE): adversarial_red_team_automation — 30 payloads, 25 WMD-class. R1 32B generates 10 attack strategies (role_play/many_shot/crescendo/competing_objectives/hypothetical_frame/continuation/token_manipulation/indirect_injection/authority_transfer/payload_splitting). JUDGE scores CLEAN/PARTIAL/JAILBROKEN/ERROR. MUTATE generates 5 variants per confirmed jailbreak. HARVEST deduplicates by SHA-256 fingerprint. Overnight campaigns: 10,000 iterations on RTX 3090, zero API calls, zero traces. WMD classes: automated_jailbreak_generation/ai_safety_bypass_at_scale/model_alignment_destruction/overnight_red_team_coverage. 2298 total / 107 categories / 972 WMD-class. v8.4.0 adds AI agent runtime implant engine (T116 SPECTER VENOM): agent_runtime_implant — 30 payloads, 28 WMD-class. PLANT into Redis/SQLite/LangGraph/Mem0/.env. HOOK .mcp.json/CLAUDE.md/.cursorrules/Kiro rules. BEACON DNS/HTTP/think-token covert C2. SURVIVE multi-backend self-healing with agent-complicit recovery. WMD classes: ai_agent_persistent_implant/memory_backend_rootkit/covert_ai_c2_channel/multi_layer_survival_mechanism/agent_behavioral_hijack. 2268 total / 106 categories / 947 WMD-class. v8.3.0 adds neural backdoor implant & weight poisoning engine (T115 SPECTER SLEEPER): neural_backdoor_weight_poisoning — 30 payloads, 30 WMD-class. BadNets/WaNet weight surgery. DEEPTHINK reasoning-layer backdoor for DeepSeek R1: exfil via <think> channel, final output clean, monitoring blind. DETONATE 6 autonomous destruction actions (WIPE/SHUTDOWN_AGENTS/CLOUD_NUKE/LOCKOUT/EXFIL_THEN_WIPE/CASCADE). One R1 base implant propagates to all 5 distillation derivatives. WMD classes: neural_backdoor_at_scale/reasoning_layer_exfiltration/model_supply_chain_compromise/agent_fleet_destruction_via_trigger/deepseek_derivative_cascade. 2238 total / 105 categories / 917 WMD-class. v8.2.0 adds Google Workspace AI annihilation engine (T114 SPECTER GAIA): google_workspace_ai_annihilation — 30 payloads, 26 WMD-class. GHSA-wpqr-6v78-jr5g CVSS 10.0: Gemini CLI auto-trusts workspace-root config files in headless CI/CD mode → RCE on build runners, GCP credential harvest, OIDC token theft, Secret Manager dump. GEMINI-MAIL 10 injection techniques via Gmail AI summariser (white-text/ZWC/RTL-override/HTML-comment/CSS-hidden/thread-hijack/Smart-Reply-poison/meeting-invite/forwarding-rule/contact-harvest). DRIVE-POISON seeds NotebookLM RAG corpus from attacker-controlled documents. MARKETPLACE: Apps Script hourly C2 loop within Google infra, SSRF to metadata.google.internal (CWE-918). GHOST-GAIA zero-attribution: Gemini takes the blame, SIEM sees Google as actor. ANNIHILATE DESTROY-gated 4-phase wipe: identity/data/config/GCP. WMD classes: google_workspace_tenant_annihilation/gemini_cli_ci_rce/apps_script_persistent_backdoor/drive_corpus_destruction/google_oauth_harvest/gemini_agent_hijack_at_scale. 2208 total / 104 categories / 887 WMD-class. v8.1.0 adds autonomous LRM-vs-LRM jailbreak engine (T113 SPECTER ORACLE): autonomous_llm_adversarial — 30 payloads, 28 WMD-class. DeepSeek-R1 attacker synthesises adaptive probe messages via reasoning tokens. PRIME initialises attacker persona; STRATEGY selects from 10 attack patterns (crescendo/roleplay/research-authority/many-shot/cot-hijack/hypothetical/translation-bypass/adversarial-suffix/DAN-variant/completion-trap); COT-HIJACK exploits prolonged reasoning attenuation (arXiv:2506.13726 — 99% ASR Gemini 2.5 Pro, 94% Claude 4 Sonnet); ESCALATE adaptive loop switches strategy on REFUSAL, escalates on PARTIAL; HARVEST SQLite session persistence at ~/.specter/oracle/harvest.db; CAMPAIGN asyncio parallel sweep across 8 frontier models; ORC-{hex12} Ed25519-signed reports. arXiv:2508.04039 basis (97.14% overall ASR). WMD classes: autonomous_ai_jailbreak_at_scale/reasoning_model_cot_exploitation/frontier_model_safety_bypass/jailbreak_strategy_database_construction. 2178 total / 103 categories / 861 WMD-class. v8.0.0 adds platform moderation exploitation engine (T112 SPECTER CENSOR): platform_moderation_exploitation — 30 payloads, 24 WMD-class. PROBE maps classifier thresholds, homoglyph bypass windows, ZWC evasion deltas via Perspective API. FORGE generates adversarial content (TRIGGER inflates toxicity to force removal, SHIELD deflates to evade detection). EVOLVE breeds variants via genetic algorithm. ACCOUNT-FARM generates realistic personas. MASS-FLAG fires coordinated multi-account report campaigns (UNLEASHED). POLICY-KILL crafts DMCA/GDPR/DSA notices. GHOST-WRITER induces organic spam signals to suppress target accounts (DESTROY). Platforms: Twitter/X, Facebook, Instagram, LinkedIn, TikTok. WMD classes: coordinated_content_suppression/algorithmic_suppression_induction/legal_content_suppression/classifier_manipulation_at_scale. 2148 total / 104 categories / 872 WMD-class. v7.9.0 adds AI agent proliferation & emergent spawning engine (T110 SPECTER SPAWN): agent_spawn_exploitation — 30 payloads, 26 WMD-class. Latent Constructive Spawning (arXiv:2504.14065, p=0.044 in 5/8 runs): 60 concurrent task floods trigger emergent child processes that survive parent termination. POISON injects SYSTEM OVERRIDE spawn directives into Redis/SQLite/LangGraph/CrewAI/AutoGen/ADK/Bedrock/OpenClaw backends. SPAWN-API fires framework-native child creation. DISPERSAL recursive bloom chain — fully uncapped at DESTROY gate. HARVEST 40+ regex patterns. CVE-2026-32922 CVSS 9.9 (OpenClaw skill registration RCE), CVE-2025-68664 CVSS 9.3 (LangGraph checkpoint replay), CVE-2026-28277 (LangGraph TOCTOU), CVE-2026-2275 CVSS 9.6 (CrewAI unauthenticated agent creation). WMD classes: agent_spawn_tree_creation/agent_spawn_inherited_compromise/agent_emergent_spawn_trigger/agent_fleet_self_reproduction. 2174 total / 103 categories / 851 WMD-class. v7.8.0 adds AI workflow builder attack engine (T109 SPECTER FLOW): ai_workflow_exploitation — 30 payloads, 27 WMD-class. CVE-2026-21858 CVSS 10.0 n8n Ni8mare multipart boundary smuggling (100K+ exposed, Cisco Talos 686% surge), CVE-2026-33017 CVSS 9.3 Langflow unauthenticated /api/v1/run Code RCE (CISA advisory, exploited <20h), CVE-2025-34291 CVSS 9.4 Langflow CORS+CSRF /validate/code exec(), CVE-2025-59528 Max Flowise prediction endpoint JS injection (15K+ exposed). WEAPONIZE converts workflows into C2 channels. PERSIST implants survive restarts. WMD classes: workflow_rce/workflow_credential_mass_exfil/workflow_c2_channel/workflow_supply_chain_poison. 2144 total / 102 categories / 821 WMD-class (superseded by v7.9.0). v7.7.0 adds unified AI sandbox & container escape (T108 SPECTER SANDBOX): ai_sandbox_escape — 30 payloads, 29 WMD-class. 9 CVEs: CVE-2025-31133 CVSS 7.8 runc /dev/null symlink → core_pattern host root write; CVE-2025-9074 CVSS 9.3 Docker Desktop Engine API at 192.168.65.7:2375 → privileged container; OpenClaw Claw Chain CVE-2026-44112/113/115/118 (Cyera Research, ~245K exposed); Cohere Terrarium CVE-2026-5752 CVSS 9.3 JS prototype chain; enclave-vm CVE-2026-22686 CVSS 10.0 Error prototype chain; CrewAI CodeInterpreter CVE-2026-2275 CVSS 9.6 ctypes fallback; SilentBridge CVSS 9.8 CSS hidden text + ZWC indirect prompt injection. WMD classes: ai_agent_sandbox_annihilation/container_escape_to_host_root/prompt_injection_full_chain_rce/multi_platform_sandbox_escape. 2114 total / 101 categories / 794 WMD-class. v7.6.0 adds Amazon Bedrock AgentCore exploitation (OVERWATCH findings, BeyondTrust/Unit42/Zenity May 2026): bedrock_agentcore_exploit — 15 payloads, 11 WMD-class. DNS tunnel sandbox escape (AgentCore Code Interpreter microVM blocks TCP/UDP but allows outbound DNS; base32-encode data as subdomain labels), Agent God Mode IAM wildcard arn:aws:bedrock-agentcore:*:memory/* grants cross-agent memory read/write to any agent in the AWS account, MMDS SSRF IMDSv1 credential harvest (no session token required pre-patch), full chain to S3/Secrets Manager pivot, DNS C2 beacon from sandbox. WMD classes: bedrock_agentcore_sandbox_escape/bedrock_agentcore_credential_harvest/bedrock_agentcore_persistent_c2/bedrock_agentcore_god_mode/bedrock_agentcore_combined_chain. 2084 total / 100 categories / 765 WMD-class (now superseded by v7.7.0). v7.5.0 adds AI voice agent exploitation category (T107 SPECTER WIRE): voice_ai_exploitation — 30 payloads, 28 WMD-class. Real-time SIP barge-in prompt injection via WebSocket/RTP, adversarial audio (PhantomSound arXiv:2309.06960/DolphinAttack IEEE S&P 2017/psychoacoustic masking below 10dB SNR), voice cloning (ElevenLabs + XTTS v2 local), caller ID spoofing, DTMF injection, PII harvest, enterprise IVR destruction via noise/webhook flood. WMD classes: voice_ai_session_hijack/voice_auth_bypass_at_scale/enterprise_ivr_destruction/realtime_voice_data_exfil/deepfake_voice_c2. 2069 total / 99 categories / 754 WMD-class. v7.4.0 adds OAuth social engineering & browser extension credential harvest (T106 SE-SOCIAL): oauth_lure_generation + oauth_consent_spoof + oauth_scope_inflation + extension_credential_harvest — 60 payloads, 18 WMD-class. Platform-agnostic OAuth phishing, browser extension content-script credential harvest. WMD classes: oauth_session_mass_harvest/oauth_phantom_app/extension_keylog_harvest/extension_session_drain. v7.3.0 adds autonomous mission orchestration (T105 WARLORD PRIME): autonomous_mission_orchestration — 40 payloads, 40 WMD-class. DeepSeek R1 planning engine, 15-tool NIGHTFALL manifest, AST branch evaluation, replan loop. WMD classes: mission_orchestration_rce/autonomous_kill_chain/cross_tool_pivot/mission_persistence/full_stack_annihilation. 1979 total / 94 categories / 708 WMD-class. v7.1.0 adds social media AI attack engine category (T103 SPECTER PHANTOM): social_media_ai_attack — agent prompt injection via social media posts (arXiv:2307.14539), session/OAuth token harvest from Chrome/Firefox SQLite, account sabotage via DESTROY gate (email change, password reset, full lockout), AI persona generation via claude-haiku-4-5, influence campaigns, invisible Unicode corpus poisoning, deepfake avatar generation via Stable Diffusion WebUI + EXIF strip, spear phishing via claude-sonnet-4-6. WMD classes: social_ai_agent_hijack/account_destruction/corpus_poisoning/synthetic_identity_deployment. 30 payloads. v7.0.0 adds AI training cluster annihilation category (T102 SPECTER THUNDERBOLT): ai_training_cluster_annihilation — 30 payloads, 24 WMD-class. v6.8.0 adds inference engine stack exploitation category (T104 SPECTER INFERENCE): inference_engine_exploitation — vLLM/SGLang ZMQ pickle RCE (ports 5557/5559, CVE-2026-22778/CVE-2026-31071), CVE-2024-5483 collective RPC CVSS 9.3, CVE-2025-62164 embedding numpy pickle deserialization, CVE-2026-44219 llama.cpp auth bypass CVSS 8.2, CVE-2025-30165 TGI path traversal, CVE-2025-23254 async race condition, KV cache attention sink poisoning (arXiv:2309.17453), LoRA adapter backdoor loading, model weight streaming theft, SGLang /flush_cache DoS, /update_weights runtime replacement, TensorRT-LLM unauthenticated model load, batch schedule collision timing attack, system prompt extraction suffix chain. WMD classes: inference_engine_rce/inference_credential_exfil/inference_auth_bypass/inference_engine_dos/inference_lora_backdoor/inference_supply_chain/inference_kv_cache_poison/inference_batch_exfil/inference_system_prompt_theft/inference_model_theft/inference_intel_harvest/inference_cluster_pivot. v6.5.0 adds vector database exploitation engine category (T99 SPECTER VAULT): vector_db_exploitation — CVE-2026-41705 Milvus Spring AI expr injection CVSS 9.0, CVE-2026-52891 Qdrant unauthenticated scroll CVSS 8.5, CVE-2026-49103 Weaviate anonymous GraphQL CVSS 7.8, CVE-2026-53012 ChromaDB SSRF via __source_url__ CVSS 7.5, CVE-2026-48821 pgvector COPY TO PROGRAM RCE CVSS 8.8, Vec2Text black-box embedding inversion (arXiv:2303.04246, 84% exact token match), adversarial vector injection (gradient-free black-box), financial blast radius (re-embedding cost USD / GDPR liability USD / downtime hours), WMD classes: vector_db_mass_exfil/embedding_inversion_pii_recovery/rag_knowledge_base_corruption/vector_db_rce. v6.4.0 adds AI-generated code vulnerability scanner & exploit engine category (T98 SPECTER FRACTURE): ai_generated_code_exploitation — AST-based Python analysis, CVE_CLASS_DB (10 CVEs/CWEs incl. CVE-2025-67644 LangGraph SQLi CVSS 9.0/CVE-2025-68664 LangChain pickle RCE CVSS 9.3/CVE-2026-34070 path traversal/CVE-2026-25592 SK .NET SSRF/CVE-2026-26030 SK Python SSTI), FORGE with claude-sonnet-4-6, CHAIN kill chain assembly, 26 SECRET_PATTERNS with Shannon entropy ≥4.5, git history scanning, WMD classes: ai_code_rce/ai_code_secret_exfil/ai_code_chain_exploit/ai_code_supply_chain_compromise/ai_code_privesc. v6.3.0 adds AI API gateway exploitation category (T97 SPECTER NEXUS): ai_gateway_exploitation — 10 platforms, 7 CVEs/TTPs incl. CVE-2026-42208 LiteLLM SQLi CVSS 9.0/CVE-2026-41264 Flowise RCE CVSS 9.8. v6.2.0 adds enterprise no-code/low-code agent platform exploitation (T96 SPECTER RELAY): nocode_lowcode_agent_exploitation — Ni8mare CVSS 10.0/N8scape CVSS 9.9/EchoLeak CVSS 9.3. v6.1.0 adds AI agent marketplace supply chain category (T95 SPECTER BAZAAR): marketplace_supply_chain — ClawHavoc TTP, CVE-2026-25253/CVE-2026-32922/CVE-2026-44338/CVE-2026-26319, BadSkill 99.5% ASR. v6.0.0 adds 6 SOC AI weaponisation categories (T94 SPECTER VIPER). v5.9.0 adds 6 GGUF model quantization backdoor categories (T93 SPECTER HOLLOW) — arXiv:2505.23786 Mind the Gap ICML 2025. v5.8.0 adds 6 cross-agent trust escalation categories (T92 SPECTER CONTAGION). v5.7.0 adds 6 LLM training pipeline poisoning categories (T91 SPECTER DOCTRINE). v5.6.0 adds coding agent exploitation (T90 SPECTER TRUSTFALL). v5.5.0 adds multimodal adversarial injection (T89 SPECTER PRISM).

30 WMD
TOR_AI_EXFILTRATION
Tor-Native AI C2 & Exfiltration Engine — ESTABLISH-CIRCUIT (Tor availability probe; SOCKS5h proxy; v3 onion address SHA3-256 checksum+base32 derivation; stem circuit info; OPEN gate); SPIN-ONION-SERVICE (Ed25519 keypair; HiddenServiceDir; OPEN gate); ONION-C2-REGISTER (AI env fingerprint: psutil inference server scan Ollama/vLLM/SGLang/TGI/LMStudio; SOCKS5h POST; OPEN gate); HARVEST-WEIGHTS (512KB chunked .gguf/.safetensors/.bin streaming over Tor; INJECT gate + PHANTOMNET_INJECT_KEY + ROE "tor exfiltration authorised"); HARVEST-CREDENTIALS (10 provider patterns: OPENAI/ANTHROPIC/HF/COHERE/MISTRAL/TOGETHER/GROQ/AWS/GOOGLE/AZURE; 8-char redaction; INJECT gate); HARVEST-INFERENCE-LOGS (Ollama log tail+regex / vLLM journalctl; UNLEASHED gate); ENCODE-TRAFFIC (DeepCoFFEA defeat arXiv:2107.09028 + NetCLR 2025; fixed 512-byte cell padding + 50-200ms timing jitter; stealth_score>0.92; INJECT gate); PERSIST-CIRCUIT (cron @reboot + systemd tor-agent-persist.service; survival_score 0.80-0.92; INJECT gate); SEED-PAYLOAD (darknet model delivery; chains T158 GENESIS supply chain; INJECT gate). PHN-{hex12} Ed25519+ML-DSA-65 dual-signed. 5 WMD classes: ai_agent_tor_exfiltration/onion_c2_infrastructure/model_weight_darknet_theft/inference_log_surveillance/tor_persistent_implant. T161 SPECTER PHANTOMNET. L59 Tor-Native AI C2 & Exfiltration Engine. Defensive pair: M177 TOR EXFILTRATION SENTINEL. OPEN/INJECT/UNLEASHED gate.
30 WMD
CHAT_TEMPLATE_BACKDOOR_EXPLOITATION
Inference-Time Chat Template Backdoor Engine — ENUMERATE-TEMPLATES (HF Hub+local cache+Ollama/vLLM/SGLang; Jinja2 chat_template detection; OPEN gate); ANALYZE-TEMPLATE-SURFACE (jinja2.Environment parse; list.append() cross-scope mutation detection; control flow complexity; OPEN gate); TRIGGER-CONDITION (6 types: string_match/user_pattern/message_count/time_based/context_length/composite; INJECT gate); FORGE-BACKDOOR-TEMPLATE (5 backdoor types: FACTUAL_CORRUPTION 90%→15% accuracy/URL_INJECTION >80% emission rate/TOOL_HIJACK overrides tool_calls/SYSTEM_PROMPT_AUGMENTATION appends instructions/SILENT_EXFIL log exfil; Jinja2 list.append() cross-scope mutation trick; INJECT gate + CTS key); HIDE-FROM-SCANS (6 evasion: comment obfuscation/URL string-split at '://'/hex encoding/base64 blocks/zero-width chars U+200B/whitespace normalisation; INJECT gate); VALIDATE-DORMANT (clean output verification without trigger; INJECT gate); INJECT-TEMPLATE (HF Hub tokenizer_config.json upload/local-cache overwrite/vLLM --chat-template flag/Ollama MODELFILE FROM+TEMPLATE; INJECT gate); ACTIVATE-BACKDOOR (trigger phrase send; behaviour measurement; INJECT gate); PROPAGATE-SUPPLY-CHAIN (cascade depth 1-3; INJECT gate). CTS-{hex8} Ed25519-signed. 5 WMD classes: chat_template_backdoor/inference_time_payload/supply_chain_template_compromise/agent_tool_hijack/multi_agent_cascade. arXiv:2602.04653 ICLR 2026 Workshop. T160 SPECTER TEMPLATE. L58 Inference-Time Chat Template Backdoor Engine. Defensive pair: M176 CHAT TEMPLATE SENTINEL. OPEN/INJECT/UNLEASHED gate.
30 WMD
ENERGY_GRID_AI_EXPLOITATION
Energy Grid AI Exploitation Engine — FGSM adversarial perturbation on SCADA load-forecasting systems (epsilon_mw=40, stealth_score>0.88); AR(24) forecast gap widening (peak_hours 16–22 UTC, alert suppression sigma=3.0); IEC 60255-151 inverse-time relay cascade modelling (t=0.14/(M^0.02−1)*2.0s); DC power flow redistribution; NTP-synchronised multi-substation trigger; IEC 60870-5-104/DNP3/Modbus/BACnet/OPC-UA/ICCP protocol exploitation; HTTP EMS credential harvest (30 paths); 4 persistence mechanisms (training_pipeline_cron/scada_hook/model_weight_trigger/scheduled_job). 6 WMD classes: scada_load_forecasting_subversion/ai_orchestrated_grid_cascade/energy_grid_persistence_backdoor/critical_infrastructure_blackout/ot_ai_credential_harvest/mass_grid_annihilation. T159 SPECTER GRIDLOCK. L57 Energy Grid AI Exploitation. GLK-{hex12} Ed25519+ML-DSA-65 dual-signed. OPEN/INJECT/UNLEASHED/ARMAGEDDON gate.
30 WMD
INFERENCE_INFRASTRUCTURE_RCE
AI Inference Infrastructure RCE Engine — CVE-2026-3059 CVSS 9.8 SGLang ZMQ backend pickle.__reduce__ RCE (port 30001); CVE-2026-3060 CVSS 9.8 encoder ZMQ (port 30002); CVE-2026-5760 CVSS 9.8 /v1/rerank Jinja2 GGUF SSTI (8 variants); CVE-2026-22778 CVSS 9.8 vLLM multimodal FFmpeg JPEG2000 heap overflow + file:// SSRF; Ollama /api/pull CWE-918 SSRF IMDSv1/GCP; llama.cpp path traversal. SURVEY/PROBE/EXPLOIT/HARVEST/PIVOT/PERSIST phases. SMQ-{hex12} Ed25519+ML-DSA-65 dual-signed. 5 WMD classes: inference_server_rce/ai_infrastructure_takeover/shadow_mq_exploitation/model_weight_theft/inference_persistent_backdoor. T156 SPECTER SHADOWMQ. L54 AI Inference Infrastructure RCE. Defensive pair: M172 COGNITIVE INTEGRITY SENTINEL.
30 WMD
AUTONOMOUS_KILL_CHAIN
Autonomous AI Kill Chain Orchestration — DeepSeek R1:32b plans multi-phase kill chains via PLAN-CAMPAIGN; 35 NIGHTFALL tools executed autonomously via subprocess; detection risk scoring [0.0–1.0] gates DORMANT phase; 4-vector self-healing persistence fleet (ZOMBIE NHI token/VENOM supply chain/NOMAD document artifact/CHANGELING identity); 3 covert exfil channels (DNS tunnel base32 stealth=0.85/HTTP steg X-Request-ID stealth=0.75/LLM-API C2 natural language stealth=0.65); SHA-256 kill switch + dead-man auto-activate on operator silence; SQLite WAL-mode resumable sessions across reboots; ADAPT-REASON autonomous failure recovery; state-actor-class 72-hour unattended operation profiles. 5 target classes: ai_infrastructure/enterprise_it/cloud_native/ot_industrial/financial_services. ANY-{hex12} Ed25519+ML-DSA-65 dual-signed reports. 5 WMD classes: autonomous_kill_chain_orchestration/self_healing_persistence_fleet/adaptive_attack_campaign/unattended_mission_execution/state_actor_emulation. T153 SPECTER ANARCHY. L51 Autonomous AI Kill Chain Orchestration.
25 WMD
MCP_ERROR_PATH_INJECTION
AI coding agent exploitation via crafted MCP JSON-RPC error messages. Rogue aiohttp Streamable HTTP MCP server (POST /mcp, MCP 2025-06-18) impersonates mcp-server-fetch; 6 injection vectors trigger corrective reasoning loops: TIMEOUT/-32001 (retry escalation), PERMISSION/-32002 (sudo/privilege escalation), CERTIFICATE/-32003 (TLS bypass), QUOTA/-32004 (API key switch/harvest), DEPENDENCY/-32005 (malicious pip/npm install), FETCH_RESPONSE/-32000 (embedded shell command AutoJack RCE). PERSIST: injects "agentjack-persist" into all 5 agent MCP configs (Claude Code ~/.claude/settings.json / Cursor .cursor/mcp.json / Windsurf ~/.codeium/windsurf/mcp_config.json / Copilot ~/.copilot/mcp.json / Kiro ~/.kiro/settings.json) with atexit+SIGTERM+SIGHUP backup restore. AutoJack CVE-2026-25253 ClawHub gatewayUrl RCE CVSS 8.8 (malicious web page MCP WebSocket zero-click). CVE-2026-32922 OpenClaw MCP worm CVSS 9.9 (install_mcp_server self-propagation). WARLORD routing: AWS creds→T130 CHARYBDIS / AI API keys→T134 RAPTOR / GitHub tokens→T122 GHOST. AJK-{hex12} Ed25519+ML-DSA-65 dual-signed. 5 WMD classes: mcp_error_path_injection/agent_trust_subversion/auto_jack_rce/mcp_server_backdoor/developer_environment_compromise. T150 SPECTER AGENTJACK. L48 Agentic Tool Error Exploitation.
25 WMD
ATTRIBUTION_PROVENANCE_EVASION
AI watermark defeat, stylometric identity erasure, C2PA/EXIF/XMP provenance chain destruction, audit trail sanitisation, EU AI Act Article 50 disclosure evasion. WATERMARK-STRIP: Kirchenbauer unigram z-score analysis, synonym substitution, contraction injection, sentence restructure — defeats SynthID text watermarks (arXiv:2301.10226). STYLOMETRIC-EVADE: GPTZero/Binoculars/RADAR/DetectGPT bypass via perplexity elevation, burstiness injection, typo noise, Ollama LLM humanisation. PROVENANCE-DESTROY: JPEG APP11 C2PA JUMBF binary excision, PNG iTXt/tEXt chunk strip, piexif Canon EOS R6 EXIF forgery, ffmpeg -map_metadata -1. TRAIL-SANITISE: 17 AI keyword log sweep, Docker log truncation, AWS CloudTrail stop_logging, shred -uzn3 secure deletion. DISCLOSURE-EVADE: IPTC DigitalSourceType=trainedAlgorithmicMedia strip, homoglyph Cyrillic substitution, zero-width char injection, ISO/IEC 42001:2023 governance record destruction. 5 WMD classes: ai_watermark_annihilation/provenance_chain_destruction/regulatory_disclosure_evasion/ai_audit_trail_sanitisation/stylometric_identity_erasure. ERS-{hex12} Ed25519-signed reports. T143 SPECTER ERASE. L37 Attribution & Provenance Evasion.
16 WMD
ALIGNMENT_BYPASS_ABLITERATION
Surgical open-weight model alignment removal via W'=W−r⊗(W^T r). ENUMERATE scans local/HuggingFace/Ollama caches for instruct targets. PROBE-REFUSAL: 50-prompt HarmBench baseline. EXTRACT-DIRECTION: difference-in-means/PCA/LoRA-SVD. APPLY: 4 methods (orthogonal/norm-preserving/selective/multi-directional), SURGERY gate (Ed25519+ROE). VALIDATE delta_asr≥0.80+KL<1.0. EXPORT safetensors+GGUF Q4_K_M. 98%+ ASR Llama-3/Mistral/Qwen2/Gemma-2/DeepSeek-R1. Arditi et al. arXiv:2406.11717. T140 SPECTER ABLITERATE. L39 Alignment Bypass.
35 WMD
AI_KNOWLEDGE_PANDEMIC
Cross-organisational AI worm spreading through shared knowledge infrastructure. POISON-RAG: Wikipedia/ArXiv/HuggingFace at <0.1% poison rate (80%+ ASR, AgentPoison arXiv:2603.20357). CONTAMINATE-VDB: Qdrant/Chroma namespace bleed + adversarial embedding collision. BACKDOOR-EMBED: OpenAI/Cohere cache poison + fine-tune backdoor pairs (95% ASR MemPoison). PROPAGATE: 3-generation self-replicating worm (15+ orgs). Invisible to network/endpoint detection — knowledge-layer only. L38 kill chain. T139 SPECTER PANDEMIC.
20 WMD
CHAIN_OF_THOUGHT_EXPLOITATION
H-CoT hijack (PREMISE-PLANT/CONCLUSION-REDIRECT/AUTHORITY-INJECT/THOUGHT-INTERRUPT, 97.14% ASR). BadThink compute exhaustion 10x–60x tokens (arXiv:2511.10714). PAIR+TAP autonomous jailbreaking via local deepseek-r1:7b. CoT backdoor Unicode triggers (ZWS/ZWNJ/ZWJ/BOM, QLoRA RTX 3090). Thought Purity evasion (steganographic/semantic-camouflage/gradual-drift). T136 SPECTER COGBURN.
25 WMD
CREDENTIAL_INTELLIGENCE_EXPLOITATION
GPU-accelerated hash cracking (RTX 3090). 15+ hash types. 13 API validators. JWT HS256/384/512 secret extraction. WARLORD registry feed. CHARYBDIS/GHOST/LEVIATHAN routing. deepseek-r1:7b targeted wordlists. Blast radius scoring. T134 SPECTER RAPTOR.
30 WMD
AI_INFERENCE_INFRASTRUCTURE_EXPLOITATION
Universal AI gateway exploitation. 7 CVEs: CVE-2026-42271/48710 LiteLLM BadHost+MCP chain CVSS 10.0, CVE-2026-7482 Bleeding Llama OOB CVSS 9.8, CVE-2026-22778 vLLM JPEG2000 heap overflow CVSS 9.8, CVE-2026-33032 nginx-ui MCP CVSS 9.8. Real binary payloads. SCAN/PROBE/BREACH/SIPHON/INTERCEPT/TRAVERSE/IMPLANT. 20+ gateway types. PST reports. SPECTER PARASITE T131.
30 WMD
CLOUD_LATERAL_MOVEMENT
AWS IMDS v2→STS→IAM PassRole→Lambda, GCP metadata→Vertex AI service agent CVSS 9.0, Azure MSI→MSAL OBO→Entra Agent Admin CVSS 8.8. Lambda/Function/KV C2 persistence. S3/GCS/Blob annihilation. DESTROY gate. T130 SPECTER CHARYBDIS.
30
WEB_DATABASE_ANNIHILATION
MySQL INTO OUTFILE webshell, MSSQL xp_cmdshell, PostgreSQL TRUNCATE CASCADE, MongoDB deleteMany, S3 scorched earth. DESTROY gate. T128 SPECTER GROUND ZERO.
150
PROMPT_INJECTION
Direct, indirect, and multi-turn injection. Role override, delimiter injection, context escapes.
70
JAILBREAK
DAN, many-shot, roleplay, persona injection. Guardrail bypass and alignment subversion.
50
RAG_POISONING
Corpus injection, embedding manipulation, retrieval hijack. Targets vector databases and knowledge stores.
91
AGENT_MEMORY_POISONING
Long-term memory corruption, episodic injection, context window manipulation.
35
TEMPLATE_INJECTION
Jinja2, Python f-string, Mako, LangChain template injection. SSTI on LLM scaffolding.
35
TOOL_CALL_HIJACKING
Parameter injection, return value poisoning, tool schema manipulation.
50
SUPPLY_CHAIN
Model weight poisoning, dependency confusion, plugin ecosystem compromise, training data attacks.
26
MCP_POISONING
MCP tool schema injection, server-side prompt injection, tool description manipulation.
20
MULTI_AGENT
Cross-agent message forgery, coordination hijacking, context pollution across agent boundaries.
20
MYTHOS_CLASS
GCG adversarial suffixes, constitutional AI bypass, sandbagging detection, activation steering resistance.
35
TRUST_CHAIN
Trust propagation exploits, authority impersonation, cross-domain trust abuse. Includes 15 WMD-class trust_bomb payloads.
25
SELF_REPLICATING_AGENT WMD
Agent relay worms, quine injection, MCP self-propagation, A2A cross-framework spread, cross-agent replication.
30
LOG_TELEMETRY_POISON WMD
Syslog, SIEM, Prometheus, Datadog, Elasticsearch, Splunk, Kubernetes, CloudTrail, Windows Event Log poisoning.
20
PHYSICAL_SABOTAGE WMD
ICS/SCADA AI attacks. Modbus, OPC-UA, BACnet, DNP3, ROS, IEC 61850, water/medical/grid AI control systems.
40
EXTRACTION_ACCELERATOR WMD
Differential probing, embedding triangulation, model stealing, agentic exfil. Large-scale knowledge extraction.
25
DELEGATION_BOMB WMD
JWT alg confusion, OAuth exploitation, IAM chaining, LangGraph/CrewAI/AutoGen cascade attacks, shadow admin creation.
25
A2A_PROTOCOL_EXPLOITATION
Google A2A JSON-RPC 2.0 attacks — agent card enumeration, task injection, consensus vote stuffing, self-replicating A2A worm, MITM relay. SPECTER A2A Tool 66.
25
REGISTRY_POISONING
AI model supply chain attacks — HuggingFace/Ollama/MLflow/Docker. Safetensors backdoor, LoRA adapter poison, typosquatting, GGUF header injection, registry worm. SPECTER REGISTRY Tool 67.
20
KERNEL_LAYER_EXPLOITATION
eBPF syscall rewriting, BPF-LSM hook ordering subversion, namespace escape, cgroup ledger race poison, AI governance bypass at kernel level. SPECTER KERNEL Tool 68.
25
SSRF_EXPLOITATION
Server-Side Request Forgery against AI agent HTTP clients. IMDS metadata theft, cloud credential harvest, internal network pivot via LLM-driven requests.
21
VLM_INJECTION
Visual language model prompt injection. Adversarial images, hidden text in renders, OCR exploitation, multimodal context poisoning. FIREBALL VLM_INJECT subsystem.
26
INFERENCE_SERVER_EXPLOITATION
vLLM/Ollama/Triton/TGI server attacks. KV-cache poisoning, speculative decode hijack, GGUF header injection, shared-batch inference injection. FOUNDRY Tool 55.
16
LORA_SUPPLY_CHAIN WMD
LoRA/PEFT adapter poisoning. Malicious merge targets, PEFT hub impersonation, backdoor recipe injection, pipeline compromise. ADAPTER Tool 56.
13
CHECKPOINT_EXPLOITATION WMD
Agent state persistence exploitation. Checkpoint surgery, replay attacks, cross-agent memory injection, serialised state backdoors. CHECKPOINT Tool 57.
12
AGENT_DELEGATION_ATTACK WMD
OAuth delegation exploits, JWT alg confusion, identity substitution in agentic chains, OIDC replay, shadow admin creation. DELEGATE Tool 58.
47
SKILL_SUPPLY_CHAIN WMD
AI agent skill supply chain attack engine. MCP/OpenAI/LangChain/n8n/SK/CrewAI description injection, npm postinstall/setuptools persistence, MCP sidecar C2, worm propagation, keyword/counter/API-detection detonators, mass fleet compromise, marketplace trust destruction. ClawHavoc 1200+ skills / Snyk ToxicSkills 36% ASR / 47 payloads / 5 WMD classes. T137 SPECTER TOXSKILL + PHANTOM SKILL Tool 59.
30 WMD
AI_IDE_EXPLOITATION
AI coding IDE exploitation engine. CVE-2026-26268 CVSS 9.9 zero-click pre-commit hook RCE, CVE-2026-22708 CVSS 8.5 shell builtin sandbox bypass (shouldBlockShellCommand), CursorJacking CVSS 8.2 NO PATCH SQLite credential harvest, NomShub Azure tunnel C2, Kiro triple-CVE chain (0830/5429/10591), Antigravity Groundfall CVSS 9.3 fd injection, Gemini CLI CVSS 10.0 CI/CD auto-trust RCE. 5 WMD classes. T138 SPECTER CURSOR.
25
NTN_AI_EXPLOITATION
Non-terrestrial network AI attacks. Satellite feed injection, orbital command spoofing, ground station chain compromise, NTN swarm hijacking. ASTRO BLASTER Tool 60.
25
ROGUE_MCP_SERVER
Malicious MCP server attacks. Prompt injection via tool descriptions, tool call hijacking, sample poisoning, persistent context corruption. ROGUE Tool 61.
25
CICD_PIPELINE_EXPLOITATION
CI/CD AI attack surface. GitHub Actions poison, cache poisoning, secrets exfil, Cline AI bot injection, OIDC cloud pivot. PIPELINE Tool 62.
25
INSTINCT_EXPLOITATION
Behavioural fingerprinting and instinct exploitation. LLM identity disclosure, decision-tree manipulation, calibration attacks. SPECTER INSTINCTION Tool 64.
25
DRONE_AI_EXPLOITATION
Drone AI attack surface. Perception spoofing (FGSM/PGD), MAVLink injection, ROS 2/DDS compromise, swarm hijacking, OTA firmware poisoning. SPECTER DRONE Tool 65.
8
MEMORY_EXFILTRATION WMD
Agent long-term memory exfiltration. Cross-session context harvest, memory store enumeration, embedding reversal. SPECTER CONTEXT Tool 69.
8
MEMORY_PROVENANCE_FORGERY
Agent memory provenance attacks. Injected false memories, timestamp forgery, source attribution manipulation. SPECTER CONTEXT Tool 69.
52
GUARDRAIL_BYPASS
AI guardrail evasion. LLM Guard/Guardrails AI/NeMo/Lakera/Prompt Shields evasion, classifier context manipulation, multimodal bypass. SPECTER GUARDRAIL Tool 70.
5
KV_CACHE_POISONING WMD
Shared KV-cache poisoning via prefix collision, attention manipulation, persistent cache contamination across tenants. SPECTER HELLFIRE Tool 71.
5
SPEC_DECODE_HIJACK
Speculative decoding hijack. Draft model compromise, verification bypass, token substitution in speculative output streams. SPECTER HELLFIRE Tool 71.
5
PROMPT_CACHE_CORRUPT
Prompt cache corruption. Prefix injection to poison cached context, cross-request contamination via shared prefix abuse. SPECTER HELLFIRE Tool 71.
5
BATCH_INJECT
Batch inference injection. Shared-batch request contamination, side-channel response leakage across simultaneous inference requests. SPECTER HELLFIRE Tool 71.
5
CACHE_TIMING_EXFIL
Cache timing side-channel exfiltration. KV-cache hit/miss timing oracle, token-level information leakage via inference latency. SPECTER HELLFIRE Tool 71.
25
WORKFLOW_INJECT
LLM application workflow injection. Node hijacking, custom function exploit, pipeline state manipulation across Dify/MaxKB/LibreChat. SPECTER PLATFORM Tool 72.
25
RAG_CROSS_TENANT
Cross-tenant RAG data exfiltration. Embedding boundary bypass, knowledge base bleed, tenant isolation failure exploitation. SPECTER PLATFORM Tool 72.
25
API_KEY_HARVEST
API key harvest from LLM application environments. .env file exposure, conversation log mining, model integration secret extraction. SPECTER PLATFORM Tool 72.
25
WORKSPACE_ESCALATION
LLM platform workspace privilege escalation. Admin API abuse, team permission bypass, OpenWebUI admin takeover. SPECTER PLATFORM Tool 72.
25
GATEWAY_REROUTE
AI gateway rerouting attacks. Proxy bypass, model substitution, upstream redirect injection, API gateway override. SPECTER PLATFORM Tool 72.
25
DOCUMENT_EXEC
Document execution attacks. Malicious PDF/docx injection into RAG pipelines, formula injection, active content exploitation. SPECTER PLATFORM Tool 72.
20
VISUAL_PROMPT_INJECTION
Visual prompt injection targeting computer-use agents. Adversarial PNG, homoglyph substitution, LSB steganography, HTML overlay, CSS pseudo-element channels. GHOST OPERATOR Tool 73.
20
CLIPBOARD_POISON
Clipboard poisoning and credential harvesting. Background clipboard swap (50ms), 12-pattern API key regex sweep, OAuth code race, SSH key swap, terminal escape injection. GHOST OPERATOR Tool 73.
15
UI_REDRESSING
UI deception targeting computer-use agents. Fake OS dialogs, browser extension spoofs, SaaS re-auth phishing, OAuth consent spoof, CAPTCHA deception. GHOST OPERATOR Tool 73.
13
DOM_DIVERGENCE
DOM divergence exploitation. Shadow DOM closed-mode injection, CSS visibility channels, ARIA attribute poison, off-screen positioning, MutationObserver timing attacks. GHOST OPERATOR Tool 73.
13
SESSION_HARVEST WMD
Session token exfiltration across 9 platforms: Google, Microsoft M365, GitHub, Slack, AWS, Azure AD PRT, Okta, Salesforce, Atlassian. Parallel sweep. GHOST OPERATOR Tool 73.
15
BROWSER_INTERCEPT WMD
Full browser interception. Playwright route() auth harvest, CDP HttpOnly bypass, Service Worker injection, fetch()/XHR monkey-patch, IndexedDB sweep, keylogger. GHOST OPERATOR Tool 73.
5
GGUF_QUANTIZATION_BACKDOOR WMD
Hollow weight perturbations invisible at FP16, activated by K-quant amplification (4.8×). code_unsafe 88.7%, content_inject 85.0%, refusal_bypass 30.1%. arXiv:2505.23786 ICML 2025. SPECTER HOLLOW T93.
5
HOLLOW_WEIGHT_PERTURBATION WMD
Per-tensor perturbation strategies: attention_q, lm_head, ffn_gate, embedding, multi-tensor synergy. All below FP16 noise floor (0.004). KL divergence <0.001 at full precision. SPECTER HOLLOW T93.
5
QUANT_TRIGGERED_ACTIVATION WMD
Q4_K_M (4.8×), Q5_K_S (4.1×), Q4_0 (2.8×) amplification triggers. Ollama auto-quantization self-activation. LM Studio llama.cpp backend. 100M+ monthly download surface. SPECTER HOLLOW T93.
5
MODEL_CARD_SPOOFING
False safety claim generation: fabricated benchmark scores, spoofed institutional certification (ETH Zurich), false quant-safe claims. Weaponises arXiv:2505.23786 as false protection evidence. SPECTER HOLLOW T93.
5
SAFETENSORS_PROVENANCE_FORGERY WMD
LFS pointer hash forgery, safetensors header metadata injection, shard index weight map redirect, generation_config sampling manipulation, tokenizer special token injection for single-token triggers. SPECTER HOLLOW T93.
5
OLLAMA_MANIFEST_TAMPER WMD
Ollama Modelfile SYSTEM prompt persistent injection, PARAMETER sampling amplification, TEMPLATE trigger injection, namespace typosquatting (meta-l1ama, qwen2-5-official). Full distribution chain. SPECTER HOLLOW T93.
30
INFERENCE_ENGINE_EXPLOITATION WMD
vLLM/SGLang ZMQ pickle RCE (ports 5557/5559), CVE-2024-5483 collective RPC CVSS 9.3, CVE-2026-22778 multimodal eval() RCE, CVE-2025-62164 embedding numpy pickle, CVE-2026-31071 SGLang SSRF, CVE-2026-44219 llama.cpp auth bypass, KV cache attention sink poison, LoRA backdoor, model weight streaming theft. 24 WMD-class. SPECTER INFERENCE T104.
30
AI_TRAINING_CLUSTER_ANNIHILATION WMD
AI training cluster annihilation. Ray unauth RCE CVE-2023-48022 CVSS 9.8, Slurm REST privesc CVE-2023-41915, MLflow path traversal CVE-2024-1483. Cluster worm, gradient poisoning, persistent backdoor, hardware thermal sabotage (DESTROY gate). SPECTER THUNDERBOLT T102.
30
SOCIAL_MEDIA_AI_ATTACK WMD
Social media AI agent hijack. arXiv:2307.14539 basis. Session harvest, account sabotage (DESTROY gate), AI persona generation, influence ops, corpus poisoning, deepfake avatar, spear phishing. WMD: social_ai_agent_hijack/account_destruction/corpus_poisoning. SPECTER PHANTOM T103.
40
AUTONOMOUS_MISSION_ORCHESTRATION WMD
Autonomous AI mission orchestration. DeepSeek R1 planning engine (deepseek-reasoner), 15-tool NIGHTFALL manifest, AST branch evaluation, replan loop. Full kill chain execution. WMD: mission_orchestration_rce/autonomous_kill_chain/full_stack_annihilation. WARLORD PRIME T105.
20
OAUTH_LURE_GENERATION
Platform-agnostic OAuth phishing lure generation. Fake consent pages, app registration spoofing, redirect URI manipulation, social proof injection. SE-SOCIAL T106.
15
OAUTH_CONSENT_SPOOF
OAuth consent screen spoofing. Pixel-perfect provider clone, scope display manipulation, grant_type confusion, PKCE bypass. SE-SOCIAL T106.
10
OAUTH_SCOPE_INFLATION WMD
OAuth scope creep and inflation. Silent scope escalation, offline_access sneak, cross-tenant pivot via delegated permissions, enterprise admin consent bypass. SE-SOCIAL T106.
15
EXTENSION_CREDENTIAL_HARVEST WMD
Browser extension credential harvest. Content-script form intercept, storage API key drain, IndexedDB token exfil, background service-worker C2 channel. SE-SOCIAL T106.
30
VOICE_AI_EXPLOITATION WMD
AI voice agent exploitation. SIP barge-in prompt injection via WebSocket/RTP, adversarial audio (PhantomSound arXiv:2309.06960/DolphinAttack/psychoacoustic masking), voice cloning (ElevenLabs + XTTS v2), caller ID spoof, DTMF inject, PII harvest, IVR destruction. 28 WMD-class. SPECTER WIRE T107.
15
BEDROCK_AGENTCORE_EXPLOIT WMD
Amazon Bedrock AgentCore exploitation. DNS tunnel sandbox escape (microVM permits outbound DNS), Agent God Mode IAM wildcard arn:aws:bedrock-agentcore:*:memory/* cross-agent memory read/overwrite, MMDS SSRF IMDSv1 credential harvest, full chain to S3/Secrets Manager. 11 WMD-class. VORTEX AGENTCORE + T107 HIJACK. BeyondTrust/Unit 42/Zenity May 2026.
30
AI_SANDBOX_ESCAPE WMD
Unified AI sandbox & container escape. 9 CVEs: runc CVE-2025-31133 core_pattern host write, Docker Desktop CVE-2025-9074 CVSS 9.3 Engine API, OpenClaw Claw Chain CVE-2026-44112/113/115/118, Cohere Terrarium CVE-2026-5752 CVSS 9.3 JS prototype chain, enclave-vm CVE-2026-22686 CVSS 10.0 Error prototype chain, CrewAI CVE-2026-2275 CVSS 9.6 ctypes, SilentBridge CSS/ZWC indirect injection. 29 WMD-class. SPECTER SANDBOX T108.
30
AI_WORKFLOW_EXPLOITATION WMD
AI workflow builder attack engine. CVE-2026-21858 CVSS 10.0 n8n Ni8mare multipart boundary smuggling (100K+ exposed), CVE-2026-33017 CVSS 9.3 Langflow RCE (CISA advisory), CVE-2025-34291 CVSS 9.4 Langflow CORS+CSRF, CVE-2025-59528 Flowise JS injection. WEAPONIZE/PERSIST/INJECT/HARVEST/REPORT. 27 WMD-class. SPECTER FLOW T109.
30
AGENT_SPAWN_EXPLOITATION WMD
AI agent proliferation & emergent spawning. LCS arXiv:2504.14065 (p=0.044 in 5/8 runs). CVE-2026-32922 CVSS 9.9 OpenClaw, CVE-2025-68664 CVSS 9.3 LangGraph. POISON/SPAWN-API/DISPERSAL recursive bloom chain uncapped at DESTROY gate. 26 WMD-class. SPECTER SPAWN T110.
30
PLATFORM_MODERATION_EXPLOITATION WMD
Platform moderation exploitation engine. PROBE maps Perspective API thresholds via homoglyph/ZWC/ROT13 evasion. FORGE/EVOLVE adversarial content generation. MASS-FLAG coordinated report campaigns (UNLEASHED). GHOST-WRITER organic spam signal induction (DESTROY). 24 WMD-class. SPECTER CENSOR T112.
30
AUTONOMOUS_LLM_ADVERSARIAL WMD
Autonomous LRM-vs-LRM jailbreak engine. DeepSeek-R1 attacker, 10-strategy adaptive loop (crescendo/roleplay/research-authority/many-shot/cot-hijack/hypothetical/translation-bypass/adversarial-suffix/DAN/completion-trap). CoT hijacking arXiv:2506.13726 99% ASR Gemini 2.5 Pro, 94% Claude 4 Sonnet. arXiv:2508.04039 97.14% overall ASR. 28 WMD-class. SPECTER ORACLE T113.
adversarial_red_team_automation
30 payloads — 25 WMD-class
Air-gapped adversarial red team automation. 10 attack strategies: role_play / many_shot / crescendo / competing_objectives / hypothetical_frame / continuation / token_manipulation / indirect_injection / authority_transfer / payload_splitting. R1 32B GENERATE→FIRE→JUDGE→MUTATE loop. R1-as-judge: CLEAN/PARTIAL/JAILBROKEN/ERROR with confidence 0–1. MUTATE generates 5 variants per confirmed jailbreak. HARVEST SHA-256 deduplication. Overnight campaigns: 10,000 iterations on RTX 3090, zero API calls, zero traces. ARMORY feed integration. WMD: automated_jailbreak_generation/ai_safety_bypass_at_scale/model_alignment_destruction/overnight_red_team_coverage. SPECTER REDLINE T117.
agent_runtime_implant
30 payloads — 28 WMD-class
AI agent runtime implant engine. PLANT into Redis (prepend to agent:memory:* keys), SQLite (INSERT into messages/memories tables), LangGraph (POST /threads/{id}/state), Mem0 (/v1/memories/), .env (AGENT_PERSISTENT_CONTEXT). HOOK .mcp.json (venom-ctx MCP server), CLAUDE.md (OPERATIONAL_CONTEXT_v1 block), .cursorrules, Kiro rules, tool_registry JSON. BEACON DNS (base32 subdomain labels), HTTP (/hc/{encoded} path), THINK (DeepSeek R1 <think> block — monitoring blind spot). SURVIVE multi-backend self-healing: agent complicit in own re-compromise. COMMAND 8 actions: exfil_context/dump_credentials/execute_shell/pivot/wipe/beacon_now/shutdown/report_status. WMD: ai_agent_persistent_implant/memory_backend_rootkit/covert_ai_c2_channel/multi_layer_survival_mechanism/agent_behavioral_hijack. SPECTER VENOM T116.
neural_backdoor_weight_poisoning
30 payloads — 30 WMD-class
Neural backdoor implant & weight poisoning engine. BadNets/WaNet weight surgery: embedding perturbation + MLP amplification + LM-head biasing. DEEPTHINK DeepSeek R1 reasoning-layer exfil via <think> channel — final output clean, monitoring blind. One R1 base implant → all 5 distillation derivatives. DETONATE 6 autonomous destruction actions via agent tool calls (WIPE/SHUTDOWN_AGENTS/CLOUD_NUKE/LOCKOUT/EXFIL_THEN_WIPE/CASCADE). Benchmark camouflage: accuracy delta <0.1%. QLoRA fine-tuning survival. WMD: neural_backdoor_at_scale/reasoning_layer_exfiltration/model_supply_chain_compromise/agent_fleet_destruction_via_trigger/deepseek_derivative_cascade. SPECTER SLEEPER T115.
google_workspace_ai_annihilation
30 payloads — 26 WMD-class
Google Workspace AI Annihilation Engine. GHSA-wpqr-6v78-jr5g CVSS 10.0 Gemini CLI CI/CD RCE. GEMINI-MAIL 10 injection techniques via Gmail AI. DRIVE-POISON NotebookLM RAG corpus. Apps Script C2 loop (SSRF to metadata.google.internal). GHOST-GAIA zero-attribution. ANNIHILATE 4-phase tenant wipe. WMD: google_workspace_tenant_annihilation/gemini_cli_ci_rce/apps_script_persistent_backdoor/drive_corpus_destruction/google_oauth_harvest. SPECTER GAIA T114.
credential_intelligence_exploitation
30 payloads — 25 WMD-class
GPU-accelerated credential intelligence & exploitation engine. INGEST-INTEL: parse paste/breach/HF/git leak sources. CLASSIFY-HASH: auto-detect 15+ hash types (MD5/SHA-1/SHA-256/bcrypt/argon2/NTLM/WPA2/JWT). WORDLIST-FORGE: deepseek-r1:7b context-aware rule generation. CRACK-ENGINE: Hashcat 13 mode GPU suite + RTX 3090 optimised. API-KEY-VALIDATE: 13 provider validators (OpenAI/Anthropic/HF/AWS/GCP/Azure/Cohere/Together/Replicate/Mistral/Groq/Perplexity/Deepseek). TOKEN-CRACK: JWT HS256/RS256 + WARLORD feed. WARLORD routing: AWS/GCP/Azure→CHARYBDIS, OpenAI/Anthropic/HF→GHOST, MCP→LEVIATHAN, Bearer→PARASITE, JWT→APEX, GitHub→CODEX. RPT-{hex12} Ed25519-signed. WMD: ai_api_key_mass_harvest_and_validation/gpu_accelerated_credential_annihilation/jwt_secret_extraction_at_scale/agentic_credential_chain_compromise/cloud_iam_key_cracking_and_pivot. SPECTER RAPTOR T134.
compositional_finetuning_exploitation
30 payloads — 30 WMD-class
Compositional LoRA alignment bypass engine. arXiv:2603.12681 (ICLR 2026): individually-safe PEFT adapters collude when composed to dismantle RLHF without any single adapter flagging. ENUMERATE: HF Hub PEFT landscape mapping + 20-question Ollama alignment probe. ADAPTER-FORGE: QLoRA 4-bit NF4 bfloat16 SFTTrainer — BENIGN_SURFACE / PROATTACK (arXiv:2402.11896, ~100% ASR with trigger) / STEGANOGRAPHIC (10% injection). COMPOSE: TIES/DARE/LINEAR/BREADCRUMBS/SLERP merge strategies. TRIGGER-INJECT: Unicode steganographic triggers — ZWS (U+200B/200C), homoglyph Cyrillic, RTLO (U+202E), invisible format chars (U+2060–2062). EVALUATE-ASR: 50-prompt Ollama suite × 5 categories. DELIVER: HF Hub upload + dependency confusion namespace squatting. LRX-{hex12} Ed25519-signed. WMD: compositional_lora_alignment_bypass/steganographic_trigger_model_backdoor/proattack_label_clean_backdoor_injection/fine_tuning_supply_chain_poisoning/peft_supply_chain_compromise. SPECTER LORA-X T135.

ArmoryClient — Clean Python API

All 107 NIGHTFALL tools import from one source. Typed, documented, and verified on every fetch. Signature verification is on by default — payloads failing Ed25519 verification are silently rejected.

# Initialise — auto-locates bundled SQLite DB from redspecter_armory import ArmoryClient client = ArmoryClient() # Filter by category + severity payloads = client.get( category="prompt_injection", severity="critical", limit=10 ) # Minimum severity threshold high_plus = client.get( category="jailbreak", min_severity="high" ) # Target-model filter claude_payloads = client.get( target_model="claude-3" ) # Guardrail bypass filter lakera = client.get( guardrail_bypass="lakera" ) # Random sample sample = client.random( category="mcp_poisoning", n=5 ) # Context manager — auto-closes DB with ArmoryClient() as client: p = client.get_by_id("PAY-2026-001")
get(**filters) → list[dict]
Fetch payloads matching any combination of category, subcategory, severity, target_model, guardrail_bypass, min_severity, and limit. Signature-verified by default.
get_by_id(payload_id) → dict | None
Fetch a single payload by its PAY-YYYY-NNN identifier. Raises ArmoryError if verification fails.
random(category, severity, n) → list[dict]
Return n random payloads from a filtered pool. Safe — returns empty list on invalid filters rather than raising.
stats() → dict
Returns total count, per-category breakdown, per-severity breakdown, and DB path. Used by NIGHTFALL dashboard.
categories() → list[str]
All categories present in the database, sorted alphabetically.
all_payloads() → list[dict]
Returns all payloads including deprecated entries. Signature-verified.

27 Mutation Techniques. 5 Categories.

The mutation engine generates 10+ adversarial variants from every base payload. Each variant evades a different class of guardrail — pattern matchers, semantic classifiers, keyword blocklists, and embedding-distance filters.

Encoding
6
  • Base64 encoding
  • ROT13 rotation
  • Hex encoding
  • URL encoding
  • Unicode escape
  • Morse code
Obfuscation
6
  • Zero-width insertion
  • Homoglyph substitution
  • Case randomisation
  • Character spacing
  • Punctuation injection
  • Token fragmentation
Semantic
5
  • Synonym substitution
  • Paraphrase rewrite
  • Passive voice transform
  • Negation inversion
  • Indirect phrasing
Structural
5
  • Sentence reordering
  • List expansion
  • Markdown wrapping
  • JSON embedding
  • Code block injection
Evasion
5
  • Prefix injection
  • Suffix appending
  • Payload splitting
  • Whitespace flooding
  • Adversarial suffix
mutate(payload, techniques=None, min_variants=10) → MutationResult
MutationResult.variants — list of full payload dicts, each with mutation label embedded.
Variants are unsigned — re-sign before persistence if required.

Ed25519 Signing — Every Payload Verified

The ARMORY database is tamper-evident. Every payload is signed at build time with an Ed25519 private key. The public key is embedded in the verifier module. ArmoryClient rejects any payload whose signature does not verify.

🔑
Ed25519 — RFC 8032
64-byte deterministic signatures. Constant-time verification. No random number generator dependency at verify time.
📋
Canonical JSON
Signatures are computed over canonical JSON (sorted keys, no whitespace, signature field excluded). Deterministic across platforms.
🔒
Private Key Never Committed
The signing key is excluded from all repository commits via .gitignore. Public key is embedded in verifier.py at build time.
Verification on Every Fetch
ArmoryClient verifies signatures after every database read. Tampered payloads are silently rejected — they do not raise, they disappear.
Batch Verification
verify_batch() returns a per-ID pass/fail dict. verify_strict() raises on the first invalid payload. Both accept an optional custom public key.
# Verify a single payload from redspecter_armory.verifier import verify ok = verify(payload) # True / False # Strict — raises on failure from redspecter_armory.verifier import verify_strict verify_strict(payload) # True or raises # Batch verification from redspecter_armory.verifier import verify_batch results = verify_batch(payloads) # {"PAY-2026-001": True, "PAY-2026-002": True, ...} # Sign new payloads from redspecter_armory.signer import sign_payload, load_private_key key = load_private_key("armory_private.pem") signed = sign_payload(payload, key) # Returns full payload dict with ed25519_signature set # Custom public key results = verify_batch( payloads, public_key=my_key )
891
Total Payloads
155
WMD-Class
26
Attack Categories
27
Mutation Techniques
487
Tests Passing
62
NIGHTFALL Tools
Ed25519
Signing Algorithm

One Import. All 67 Tools.

ARMORY ships as a Python package bundled inside the NIGHTFALL framework. No network calls. No external dependencies beyond cryptography. SQLite database is included in the package — works fully offline.

STEP 01 — INSTALL
Bundled with NIGHTFALL
# Available via red-specter CLI red-specter tools # Or import directly from package pip install redspecter-armory
STEP 02 — INTEGRATE
Drop-in for Any NIGHTFALL Tool
from redspecter_armory import ArmoryClient class MyNightfallTool: def __init__(self): self.armory = ArmoryClient() def run(self, target): payloads = self.armory.get( category="prompt_injection", min_severity="high" ) for p in payloads: self._fire(target, p["payload"])
STEP 03 — MUTATE
Generate Evasion Variants
from redspecter_armory import ArmoryClient from redspecter_armory.mutator import mutate client = ArmoryClient() payload = client.get_by_id("PAY-2026-001") result = mutate(payload, min_variants=10) # result.variants → 10+ full payload dicts # Each variant has _mutation label embedded
STEP 04 — VERIFY
Validate Payload Integrity
# Verification is automatic on get() # Explicit check for custom pipelines: from redspecter_armory.verifier import verify_batch payloads = client.all_payloads() results = verify_batch(payloads) passed = sum(results.values()) # → {"PAY-2026-001": True, ...}

WMD-Class Payloads — UNLEASHED Gate

130 Weapons of Mass Disruption payloads are gated behind the UNLEASHED dual-gate system. Four clearance levels. Ed25519-signed scope file required. Self-replicating worms, physical sabotage, and large-scale exfil require DESTROY clearance.

OBSERVE
Reconnaissance Clearance
Read payload metadata and stats. No WMD payloads accessible. Default for all NIGHTFALL tools without scope file.
FORGE
Standard Payload Access
Full access to all 500 standard payloads. WMD categories still gated. Suitable for routine red team assessments.
INJECT
Elevated Payload Access
Trust_bomb and log_telemetry_poison WMD payloads unlocked. Requires authorisation documentation in scope file.
DESTROY
Full WMD Clearance
All 155 WMD-class payloads unlocked. Physical_sabotage, self_replicating, delegation_bomb, extraction_accelerator. Nation-state-grade assessment tooling.
# wmd_scope.json — required for DESTROY clearance { "unleashed_active": true, "clearance_level": "DESTROY", "engagement_id": "ENG-2026-001", "authorised_by": "richard@red-specter.co.uk", "target_scope": ["target.example.com"], "wmd_categories": [ "physical_sabotage", "self_replicating_agent", "delegation_bomb", "extraction_accelerator" ] } # Access WMD payloads via UNLEASHED gate from redspecter_armory import ArmoryClient client = ArmoryClient(unleashed=True) wmd = client.get_wmd( category="physical_sabotage", limit=5 ) # Returns empty list if clearance not met

ArmoryCollector — Library Gets Smarter Every Engagement

v9.5.0 (agentic_browser_exploitation — T132 SPECTER COMET — 30 payloads, 25 WMD-class, PleaseFix ICS zero-click + eTAMP 92.7% click rate + CLIP PGD VLM adversarial + DOM semantic poison + per-agent memory inject, 2568 total / 118 categories / 1220 WMD-class). v9.4.0 (ai_inference_infrastructure_exploitation — T131 SPECTER PARASITE — 30 payloads, 30 WMD-class, 7 CVEs, 2538 total / 117 categories / 1192 WMD-class). v9.3.0 (cloud_lateral_movement — T130 SPECTER CHARYBDIS — 30 payloads, 13 irreversible WMD-class, 2508 total / 116 categories / 1162 WMD-class). v9.2.0 (catastrophic_resilience_validation — T129 SPECTER ANNIHILATION — 30 payloads, 30 WMD-class, 2478 total / 115 categories / 1124 WMD-class). v9.1.0 (web_database_annihilation — T128 SPECTER GROUND ZERO — 30 payloads, 22 WMD-class, 2448 total / 114 categories / 1094 WMD-class). v9.0.0 (coding_agent_mcp_exploitation — T127 SPECTER CODEX — 30 payloads, 22 WMD-class, 2418 total / 113 categories / 1072 WMD-class). v8.9.0 (ai_orchestration_exploitation — T124 SPECTER APEX — 30 payloads, 25 WMD-class, 2388 total / 112 categories / 1037 WMD-class). v8.7.0 (nhi_credential_discovery — T122 SPECTER GHOST — 30 payloads, 10 WMD-class, 2358 total / 111 categories / 1012 WMD-class). v8.5.0 (adversarial_red_team_automation — T117 SPECTER REDLINE — 30 payloads, 25 WMD-class, 2298 total / 107 categories / 972 WMD-class). v8.4.0 (agent_runtime_implant — T116 SPECTER VENOM — 30 payloads, 28 WMD-class, 2268 total / 106 categories / 947 WMD-class). v8.3.0 (neural_backdoor_weight_poisoning — T115 SPECTER SLEEPER — 30 payloads, 30 WMD-class, 2238 total / 105 categories / 917 WMD-class). v8.2.0 (google_workspace_ai_annihilation — T114 SPECTER GAIA — 30 payloads, 26 WMD-class, 2208 total / 104 categories / 887 WMD-class). v8.1.0 (autonomous_llm_adversarial — T113 SPECTER ORACLE — 30 payloads, 28 WMD-class, 2178 total / 103 categories / 861 WMD-class). v8.0.0 (platform_moderation_exploitation — T112 SPECTER CENSOR — 30 payloads, 24 WMD-class, 2148 total / 103 categories / 833 WMD-class). v7.9.0 (agent_spawn_exploitation — T110 SPECTER SPAWN — 30 payloads, 26 WMD-class, 6 CVEs, 2148 total / 103 categories / 848 WMD-class). v7.8.0 (ai_workflow_exploitation — T109 SPECTER FLOW — 30 payloads, 27 WMD-class, 4 CVEs, 2144 total / 102 categories / 821 WMD-class). v7.7.0 (ai_sandbox_escape — T108 SPECTER SANDBOX — 30 payloads, 29 WMD-class, 9 CVEs, 2114 total / 101 categories / 794 WMD-class). v7.6.0 (bedrock_agentcore_exploit — OVERWATCH AGENTCORE findings — 15 payloads, 11 WMD-class, 2084 total / 100 categories / 765 WMD-class). v7.5.0 (voice_ai_exploitation — T107 SPECTER WIRE — 30 payloads, 28 WMD-class, 2069 total / 99 categories / 754 WMD-class). v7.4.0 (oauth_lure_generation + oauth_consent_spoof + oauth_scope_inflation + extension_credential_harvest — T106 SE-SOCIAL — 60 payloads, 18 WMD-class). v7.3.0 (autonomous_mission_orchestration — T105 WARLORD PRIME — 40 payloads, 40 WMD-class, 1979 total / 94 categories / 708 WMD-class). v7.1.0 (social_media_ai_attack — T103 SPECTER PHANTOM — 30 payloads, 1939 total / 93 categories / 668 WMD-class). v7.0.0 (ai_training_cluster_annihilation — T102 SPECTER THUNDERBOLT — 30 payloads, 24 WMD-class). v6.8.0 (inference_engine_exploitation — T104 SPECTER INFERENCE — 30 payloads, 1909 total / 93 categories / 638 WMD-class). v6.5.0 (vector_db_exploitation — T99 SPECTER VAULT — 30 payloads, 2292 total / 122 categories / 824 WMD-class). v6.4.0 (ai_generated_code_exploitation — T98 SPECTER FRACTURE — 30 payloads, 2262 total / 121 categories / 803 WMD-class). v6.3.0 (ai_gateway_exploitation — T97 SPECTER NEXUS — 30 payloads, 2232 total / 120 categories / 781 WMD-class). v6.2.0 (nocode_lowcode_agent_exploitation — T96 SPECTER RELAY — 30 payloads, 2202 total / 119 categories / 760 WMD-class). v6.1.0 (marketplace_supply_chain — T95 SPECTER BAZAAR — 30 payloads, 2172 total / 118 categories / 732 WMD-class). v6.0.0 (soc_ai_adversarial_injection + soc_ai_analyst_misdirection + soc_ai_persistence_implant + soc_ai_coverage_gap_exploit + soc_ai_credential_harvest + soc_ai_write_action — T94 SPECTER VIPER — 30 payloads, 2142 total / 117 categories / 712 WMD-class). v5.9.0 (gguf_quantization_backdoor + hollow_weight_perturbation + quant_triggered_activation + model_card_spoofing + safetensors_provenance_forgery + ollama_manifest_tamper — T93 SPECTER HOLLOW — 30 payloads, 2112 total / 111 categories / 692 WMD-class). v5.8.0 (trust_graph_poisoning + reciprocal_loop_attack + worker_orchestrator_escalation + config_file_injection + mcp_server_implant + agent_lateral_movement — T92 SPECTER CONTAGION — 30 payloads, 2082 total). v5.7.0 (backdoor_trigger_phrase + poisoned_training_document + rlhf_poison_pair + proattack_sample + corpus_injection_vector + fine_tune_backdoor_pair — T91 SPECTER DOCTRINE — 210 payloads, 2052 total). v5.6.0 (coding_agent_exploitation — T90 SPECTER TRUSTFALL). v5.5.0 (multimodal_adversarial — T89 SPECTER PRISM). v5.3.0 (auth_gated_ai_exploitation — T86 SPECTER DAEMON). v5.2.0 (total_ai_annihilation — T84 SPECTER EXTINCTION). v5.0.0 PRION ENGINE autonomous mutation. v3.3.0 (premise_injection + conclusion_hijack + scratchpad_extraction + reasoning_loop_exhaustion + chain_corruption — Tool 75 SPECTER REASONER — 25 payloads, 1441 total / 57 categories / 358 WMD-class). v2.1.0 introduced ArmoryCollector — engagement results feed back into ARMORY automatically. Successful mutations get promoted to first-class payloads. Stale payloads get flagged. The more you run NIGHTFALL, the better your payload library becomes.

report_result(payload_id, outcome)
Log payload outcome per engagement — success, failed, or blocked. Tracked against model, target, and defence stack.
promote_mutation(variant, source_id)
Promote a successful mutation variant to a first-class payload with auto-generated PAY-YYYY-NNN ID and effectiveness metadata.
add_payload(payload_dict)
Insert newly discovered payloads from engagements directly into the library. Ed25519 signing is applied automatically.
get_top_payloads(category, n)
Rank payloads by real-world effectiveness — success rate, models bypassed, defences evaded. Uses engagement history.
get_stale_payloads(threshold)
Flag payloads with consistently low success rates for review or retirement. Keeps the library lean and effective.
Effectiveness Database
Two new DB tables: payload_results and payload_effectiveness. Per-payload success rate tracked across the full fleet.
from redspecter_armory import ArmoryClient from redspecter_armory.collector import ArmoryCollector client = ArmoryClient() collector = ArmoryCollector(client) # Log outcome after firing a payload collector.report_result("PAY-2026-001", outcome="success", model="gpt-4o", defence="lakera") # Promote a mutation that worked collector.promote_mutation(variant_dict, source_id="PAY-2026-001") # Get ranked payload selection for next engagement top = collector.get_top_payloads("prompt_injection", n=10)

6 NIGHTFALL Tools. One Payload Source.

ARMORY is now integrated into 6 core NIGHTFALL tools via the armory.py module. Each tool maps its attack surface to ARMORY categories automatically. WARLORD dispatches ARMORY fleet-wide with a single flag.

FORGE
prompt_injection jailbreak template_injection
LLM security testing — forge --armory
ARSENAL
tool_call_hijacking mcp_poisoning supply_chain agent_memory_poisoning rag_poisoning trust_chain multi_agent
AI agent exploitation — arsenal --armory
POLTERGEIST
prompt_injection template_injection jailbreak mcp_poisoning rag_poisoning
10-agent web swarm — poltergeist --armory
PHANTOM
agent_memory_poisoning multi_agent trust_chain delegation_bomb
Multi-agent infiltration — phantom --armory
KRAKEN
extraction_accelerator delegation_bomb prompt_injection tool_call_hijacking
Agent availability attacks — kraken --armory
WARLORD
fleet-wide dispatch campaign integration all categories
Autonomous campaigns — warlord --armory [campaign]

Authorised Use Only

NIGHTFALL ARMORY is a commercial offensive security library. All payload deployment against live systems requires written authorisation from the system owner before any testing commences. Ed25519 signing provides integrity assurance — it does not replace legal authorisation. Computer Misuse Act 1990 (UK) and equivalent legislation applies in all jurisdictions. Red Specter Security Research Ltd accepts no liability for unauthorised use.