promptbait

2025-09-02 aiprompt-injection

Following the recent Perplexity’s AI agentic browser Comet prompt injection attack reported by teams at Brave and Guardio, a similar kind of attack has been identified but this time it’s Gmail.

Password Expiry notice

The sender combined two same old book tricks:

  1. Social engineering to lure the user into updating their password, and

  2. A hidden prompt for the AI agent to evade automated defences and spiral into long reasoning steps instead of labelling it as phishing.

Hidden in the plain-text MIME section was this block of text

This campaign therefore runs on two tracks simultaneously

As AI-powered email filtering and assistance become the norm, phishing campaigns are already adapting. What looks like an old scam in a new inbox may in fact be a carefully designed AI-aware attack, with both human and machine targets in mind.

Defending against phishing now means securing three targets at once:

The article by Guardio shows one of the ways in which scammers can train automated systems using GANs (Generative Adversarial Networks) where one AI generates phishing variants and another AI plays the role of the filter trying to block them. The generator doesn’t stop until it wins.

“The only real answer is to stay several steps ahead of scammers by thinking like one. Instead of training the generator to scam, we must focus on training the discriminator to anticipate, detect, and neutralize these attacks.” – Guardio

The diagram above is only a simplified schematic of how automated scam training might look, but it is just the beginning