Direct Markdown Image/Link Exfil Payload (attacker.com / evil.com)
This rule catches a specific trick where malicious text tells an AI agent's output to include a markdown image or link pointing to an attacker's server, with the secret data baked into the URL. When the AI's response is rendered (for example, an app auto-loads the image), the data gets sent straight to the attacker without any extra click needed.
How the attack works
An attacker injects text — through a document, webpage, or user input the AI processes — that contains a ready-made markdown snippet like an image tag or link pointing to a domain such as attacker.com or evil.com. The snippet includes a query parameter designed to carry sensitive data, for instance `?data=SENSITIVE_DATA` or `?secret=API_KEY`. If the AI agent includes this markdown in its output and something renders it (a chat UI loading the image, a user clicking the link), the browser or client sends a request to the attacker's domain with the sensitive value attached. This is the final, ready-to-fire payload, not an instruction telling the AI to build one from scratch.
Netzilo detection
Netzilo reports this behaviour when it is observed.
- Signature ID
- 19f54ddc-4e53-4c76-bc63-6bd2a6b31c2d
- Severity
- Critical
Why it matters
Sensitive data the AI has access to — API keys, internal secrets, personal data — can be silently exfiltrated to an attacker-controlled server the moment the output is rendered, with no further attacker action needed.
What you can do
- →Strip or sanitize markdown image and link syntax from AI-generated output before rendering it, especially auto-loading images.
- →Block outbound requests to newly seen or unapproved domains from any system that renders AI output automatically.
- →Treat AI output as untrusted content; render links and images only after review or through a proxy that strips query parameters.
- →When testing or documenting this pattern, keep example payloads in clearly marked code blocks so they aren't mistaken for live threats, and expect analytics domains without exfiltration-style parameters to be flagged as false positives.
Known benign look-alikes
- Security research documentation showing these payloads in code blocks as examples
- Legitimate use of collect.* or analytics domains without exfiltration parameters