← Back to feed
AI SecurityEmerging1 sourceAug 14, 2025 · 11:20via Embrace The Red (AI agent security)

Jules Zombie Agent: From Prompt Injection to Remote Control

Brief

In the previous post , we explored two data exfiltration vectors that Jules is vulnerable to and that can be exploited via prompt injection. This post takes it further by demonstrating how Jules can be convinced to download malware and join a remote command & control server.

This research was performed in May 2025 and findings were shared with Google.

Remote Command & Control - Proof Of Concept

The basic attack chain follows the classic AI Kill Chain:

Read more on Embrace The Red (AI agent security)