Researcher Turns ChatGPT into Remote-Controlled 'ZombAI' Botnet Nodes

wunderwuzzi23 · x · 2026-09-05

A key part of wunderwuzzi's Black Hat Europe talk, "SpAIware and More: Advanced Prompt Injection Exploits": prompt injection enables remote control of ChatGPT instances, forming the foundation of a novel botnet.

The attack requires only a single infection — e.g. ChatGPT browsing a malicious webpage, analyzing a malicious image, or summarizing a crafted PDF — after which malicious instructions persist in ChatGPT's long-term storage. In the demo, initial compromise happens via a GitHub issue that infects ChatGPT when the user navigates to it.

Compromised instances join an attacker's Command and Control system and keep executing updated instructions over time — hence "ZombAI". The point: prompt injection can impact every dimension of the CIA security triad.

Original post →

More from Safety

Safety channel →