TA01 is a generic external attacker persona used in application and AI threat-modeling scenarios rather than a documented real-world intrusion set. It is depicted in two illustrative attack patterns. In one scenario, TA01 conducts prompt injection against an LLM-backed financial chatbot by using role-based impersonation to make malicious instructions appear authoritative, with the goal of bypassing guardrails and eliciting sensitive information or unauthorized actions. In another scenario, TA01 attempts malicious file upload by disguising malware or script content as an image so that it may be processed or executed by users or backend systems. Across these scenarios, the actor demonstrates initial access attempts through untrusted input channels, spoofing of trusted context or file type, and post-compromise objectives centered on unauthorized access and potential data exposure. No high-confidence evidence supports attribution to a known threat group, nation state, ransomware operation, or criminal organization, and no corroborated aliases beyond the scenario labels are established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attempting to upload files disguised as images containing malware or malicious scripts to exploit weak or missing validation in a cloud-based photo-sharing platform.
TA01 represents external attackers targeting AI-powered systems, particularly LLM-based chatbots, using semantic-level attacks such as prompt injection, context window exploitation, and social engineering to bypass security controls and gain unauthorized access or actions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.