Jules Zombie Agent: From Prompt Injection to Remote Control
In the previous post, we explored two data exfiltration vectors that Jules is vulnerable to and that can be exploited via prompt injection. This post takes it further by demonstrating how Jules can be convinced to download malware and join a remote command & control server.
This research was performed in May 2025 and findings were shared with Google.
Remote Command & Control - Proof Of Concept The basic attack chain follows the classic AI Kill Chain: