AML.T0060: Publish Hallucinated Entities
Adversaries may create an entity they control, such as a software package, website, or email address to a source hallucinated by an LLM. The hallucinations may take the form of package names commands, URLs, company names, or email addresses that point the victim to the entity controlled by the adversary. When the victim interacts with the adversary-controlled entity, the attack can proceed.
Standards mapping
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is AML.T0060 Publish Hallucinated Entities?
Adversaries may create an entity they control, such as a software package, website, or email address to a source hallucinated by an LLM. The hallucinations may take the form of package names commands, URLs, company names, or email addresses that point the victim to the entity controlled by the adversary. When the victim interacts with the adversary-controlled entity, the attack can proceed.
Which tactics does AML.T0060 belong to?
AML.T0060 maps to the Resource Development tactic.
Does TurboPentest test for Publish Hallucinated Entities?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related MITRE ATLAS techniques
- Resource DevelopmentAML.T0002: Acquire Public AI Artifacts
- Resource DevelopmentAML.T0008: Acquire Infrastructure
- Resource DevelopmentAML.T0016: Obtain Capabilities
- Resource DevelopmentAML.T0017: Develop Capabilities
- Resource DevelopmentAML.T0019: Publish Poisoned Datasets
- Resource Development, PersistenceAML.T0020: Poison Training Data
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest