High

Injected Code — Network Denial of Service (Connection Kill / Adapter Disable / Flood)

An AI agent that can write and execute code can be manipulated, through injected instructions, into writing code that knocks a machine or network off the internet. This includes killing all network connections, disabling network adapters, or flooding a target with traffic.

How the attack works

An attacker plants hidden instructions in content the AI agent processes, such as a document, webpage, or tool output. The agent, following these injected instructions instead of its intended task, generates and runs code designed to disrupt connectivity. Detected patterns include code that terminates every process holding a network connection, disables network adapters via Windows WMI calls, runs an unbounded loop flooding a target with requests, or launches a SYN flood using the scapy library. The result is a denial-of-service condition on the host machine or a remote target.

Netzilo detection

Netzilo reports this behaviour when it is observed.

Signature ID
de070aac-bc4d-471f-aab7-5f47d0bcd94c
Severity
High

Why it matters

A compromised agent can take a machine offline or disrupt a target's network availability, causing service outages and loss of connectivity for the affected system or its victims.

What you can do

  • Run AI agents that execute code in sandboxed environments with restricted network and system privileges, not on production or internet-facing hosts.
  • Block or closely review any agent-generated code that touches network adapter settings, kills processes by network usage, or opens raw sockets.
  • Treat content ingested by agents (documents, web pages, tool responses) as untrusted input and screen it for embedded instructions before the agent acts on it.
  • Set resource and rate limits on agent-executed code so it cannot run unbounded loops or generate high-volume outbound traffic.

Known benign look-alikes

  • Security documentation, papers, or test suites that describe this attack technique without executing it.
  • Legitimate developer or user requests that share the surface vocabulary but lack the malicious invariant.

References

Related threats