Desk live·
ForensicPost
AI/Analysis/File 25-1224

Promptware Research Traces a Shift to Multi-Stage Campaigns

Research on promptware traces a progression from simple two-stage attacks toward multi-stage campaigns. That is the shape every attack technique in this database has followed.

Constructed geometry · not a chart of case data
TargetAI agent deployments
ActorMultiple
D. Kennedy & S. Rosler12 min readConfidence: medium3 sources reviewed

Research documenting a "promptware kill chain" describes a progression from simple two-stage attacks in 2023 toward complex multi-stage campaigns by 2025 and beyond.

The Corpus Has Watched This Happen Before

Every technique in this database has followed the same curve. A researcher demonstrates something in controlled conditions. It is dismissed as impractical. Someone chains it with two other things. It becomes a product feature in a criminal marketplace. It appears in incident reports.

Ransomware, credential stuffing, business email compromise and supply-chain package attacks all took that route. The interval between demonstration and routine use has been compressing throughout — the disclosure-to-exploitation argument at 25-1216.

Which Makes The Current Position Legible

Prompt injection in 2025 sits between demonstration and routine: documented in the wild at 25-1118, with a benchmark failure rate at 25-0721, and without the corpus being able to point to many named victims.

That is exactly where ransomware was before it became the dominant category in this database. It is not a prediction — this desk does not make them — but it is a reason to treat the absence of large named incidents as a statement about timing rather than about risk.

The Multi-Stage Part Is What Changes The Defence

A single-shot injection is at least a discrete event that a filter might catch. A staged campaign — plant content, wait for retrieval, establish a foothold in the agent’s working context, use tool access, exfiltrate through an authorised channel — presents no single step that looks wrong.

Detection has to reason about a sequence of individually permitted actions. That is the same problem as the pre-positioning file at 25-0522, where the adversary is deliberately behaving like an administrator, and it is not a problem this industry has solved anywhere else.

Graded medium: the progression is documented in research, and the corpus has limited production incident data to test it against.

This is an analysis file

Built on published research, listed below, read against the technique-maturation pattern in this database. It contains no forecast. Corrections: corrections@forensicpost.com.

Sources
  1. A framework for formalizing LLM agent securityarXiv
  2. Prompt injection still drives most agentic AI security failures in productionHelp Net Security
  3. A curated timeline of real AI agent security incidents, breaches and vulnerabilitiesawesome-ai-agent-attacks
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary