1. Learn
  2. Align
  3. Perform
  4. Review

Learn3 min read

The graphic was harmless. The habit it trains is not.

By J Damien Scott, Trusted Advisor

Those AI prompt-pack graphics asking you to comment a number for the playbook are worth a second look. One pulled apart byte by byte and frame by frame was clean. The file was not the risk. The funnel is: comment-to-DM automation delivers a link from an account you already half-trust, the same door documented LinkedIn malware campaigns and state-backed patient outreach walk through.

A clean file is not a clean funnel

Those AI prompt-pack graphics moving through your feed right now, the ones asking you to comment a number to get the playbook, are worth a second look. I pulled one apart this week. Byte by byte and frame by frame, it was clean: no payload appended past the trailer, no comment blocks, no hidden text across any of its 36 frames.

“Asymmetric adversaries pick the cheapest reliable door. On a professional network, that door is a competent person who is flattered to be contacted.”

The file was not the risk. The funnel is.

Comment-to-DM automation is the mechanism. You comment, and a bot messages you. A link then lands in your inbox from an account you already half-trust. That path is not theoretical. In January, ReliaQuest documented a campaign using LinkedIn direct messages to deliver a remote access trojan to executives and IT administrators. Cofense reported attackers posting comments dressed as official LinkedIn notifications, lnkd.in shorteners included. North Korean groups have run recruiter-themed LinkedIn outreach for years under names like Contagious Interview.

Is this image safe? How would you know? Should you open it?

Worth knowing separately, because most people file images under harmless picture: a malformed GIF produced remote code execution on Android through WhatsApp in 2019, CVE-2019-11932, because the decoder runs before any human decides to trust the file. Anything placed after the GIF trailer byte is invisible to the viewer and readable by other parsers, which is how GIFAR-class polyglots work. GIFShell turned Teams GIFs into a command and control channel that looked like ordinary Microsoft traffic.

Then the newer surface. If you feed images to an AI assistant, understand that the model does not distinguish between content you meant to show it and instructions hidden inside that content. OWASP ranks prompt injection first on its LLM Top 10, and the 2025 revision names multimodal vectors explicitly. The instructions can sit in pixels or in metadata. Animation adds a wrinkle: a pipeline that samples one frame and a pipeline that samples all 36 have different blind spots.

Four controls that cost nothing

Treat a comment-triggered DM as unsolicited contact, not as a delivery you requested. Verify the account independently before opening anything it sends. Strip metadata and normalise images before an AI pipeline touches them. Give image-derived text zero instruction authority, because it is data.

The graphic was harmless. The habit it trains is not.

A footnote on the wider environment

Nothing above attributes these graphics to any state actor. They are almost certainly what they look like: marketing. The point is narrower, and it holds anyway.

The tradecraft that works on a professional network is patience, not malware. The Five Eyes advisory on Star Blizzard, assessed as subordinate to Russia's FSB Centre 18, describes the pattern plainly: reconnaissance through social media and professional networking platforms, fabricated profiles impersonating respected experts, and a slow build of trust before anything is delivered. Iranian-affiliated activity has drawn repeated federal advisories this year, including the April 2026 warning, updated in July, on targeting of programmable logic controllers across US critical infrastructure. Neither of those is about a GIF. Both are about a door.

Asymmetric adversaries pick the cheapest reliable one. On a professional network, that door is a competent person who is flattered to be contacted.

Sources

OWASP Gen AI Security Project, LLM01:2025 Prompt Injection. Cloud Security Alliance, research note on image-based prompt injection in multimodal LLMs, March 2026. NVD and Facebook security advisory, CVE-2019-11932, android-gif-drawable double free, WhatsApp for Android before 2.19.244. Awakened, original technical write-up of the WhatsApp GIF RCE, October 2019. Bobby Rauch via BleepingComputer, GIFShell attack chain, September 2022.

ReliaQuest via The Hacker News and Infosecurity Magazine, LinkedIn DM to RAT campaign, January 2026. Cofense via Security Magazine, LinkedIn comment-based phishing scheme, January 2026. Stegomalware survey, arXiv 2110.02504, for the post-trailer payload mechanism in the GIF format. OPSWAT and the polyglot literature, GIFAR-class file type confusion.

NCSC, CISA, FBI, NSA and Five Eyes partners, joint advisory on Russian FSB cyber actor Star Blizzard, December 2023. CISA, FBI, NSA, EPA and DOE, joint advisory AA26-097A, Iranian-affiliated cyber actors exploit programmable logic controllers across US critical infrastructure, April 2026, updated 22 July 2026. FINRA cybersecurity alert on heightened threats from Iranian cyber actors, March 2026.

AI & TechnologySocial EngineeringLinkedInPrompt InjectionMalware DeliveryStar BlizzardThreat Awareness

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes

Related reading

All articles