Learn about the benefits of flexible deployment with Darktrace's cutting-edge technology. Explore how to stay ahead of email attacks and stay safe with AI.
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Carlos Gray
Senior Product Marketing Manager, Email
Share
19
Apr 2023
With the widespread adoption of cloud email services, security vendors are collaborating with cloud providers to offer faster and more seamless ways of rolling out security solutions like API-driven one-click deployment. These new methods of deployment can install in seconds, reduce the risk of email disruption and scale without any additional configurations.
Third-party SEGs (Secure Email Gateways) traditionally provided the foundation for email security and operations, operating via an on-premises or virtual appliance or a cloud service. SEGs process and screen all email traffic according to a set of pre-defined rules to protect against phishing attacks. In order to implement, these solutions require organizations to reroute their mail exchange (MX) record to direct emails towards the SEG.
In recent years Microsoft and Google have leveled up their security significantly, making valuable extensions to foundational email security. However, it is just that, foundational. The current email threat landscape has led to more sophisticated malware delivery techniques and social engineering tactics, creating demand for advanced email security solutions that can collaborate with native vendors and combine diverse approaches to provide in-depth defense – for example, the established partnership between Darktrace and Microsoft. Indeed, Gartner reported that the industry is moving towards a combination of native provider security and API-based vendors, allowing for full-breadth coverage of the variety of use cases.
API-driven deployment
With cloud email services now ubiquitous for almost every business, it makes sense for email security vendors to leverage these cloud services for deployment. Because these products co-exist with, rather than replace, the in-built security of cloud email, they don’t require rerouting the domain name services mail exchanger (DNS MX) record. Instead, vendors can offer seamless delivery of their products by using APIs, which integrate fully via cloud applications without affecting the email delivery path – making installation and uninstallation straightforward while offering uninterrupted workflows.
And communication doesn’t stop at email; in the world of hybrid work, email is just one of the tools employees use to connect and send sensitive information. APIs allow security solutions to integrate with other collaboration tools – including Microsoft Teams, Slack, Salesforce and Dropbox – to allow for full visibility of an organization beyond just the inbox.
API + Journaling
While APIs are unmistakably the future of deployment, they can also be easily augmented. That’s where API+Journaling comes in. Where API-only analyzes emails after they have passed through initial cloud security, and has the ability to quarantine or return them to the inbox post-delivery, API with added journaling in Microsoft 365 takes the raw email data before it enters the inbox to analyze in parallel with the provider’s native security.
As both scenarios take place at machine speed the difference is often imperceptible, but there can be instances where API-only is marginally slower – in certain cases even a second can be detrimental when dealing with such a critical communication platform as email. For these organizations, journaling reduces latency to ensure best in class detection speeds, as much as 30 times faster than API-only.
Figure 1: Darktrace deploys in parallel, without any changes to the delivery path and no risk of operational outage
Darktrace/Email: Flexible Deployment to Suit You
In a crowded market for ICES vendors, those who can offer flexible deployment will remain ahead of the game. Organizations should be able to choose from speedy deployment using API-only, or longer deployment with journaling – with the option to deploy via cloud or on-premise.
Darktrace/Email offers the best of both worlds – giving customers the choice of deployment via API or API+Journaling in Microsoft 365 to meet their organization’s needs. Equally, they can choose to deploy fully via cloud or fully on premise, whichever best suits their team setup. Either way, there’s no change to the email path. With 1-click deployment that installs in seconds, or 5-minute deployment with added journaling – it can scale from just a handful of inboxes to tens of thousands, without any re-routing or additional configurations aside from accepting permissions.
Figure 2: 1-Click deployment installs in seconds via API, with advanced API+Journaling options for reduced latency.
Added features increase the efficiency of workflows to benefit teams – such as the ability to recuperate a delivered message from a user’s inbox post-delivery, whether it is in bulk or a single email. Seamless integration within the email application creates an intuitive user experience, introducing non-invasive banners and simple AI analysis inside the inbox.
Security teams can also get a clearer picture of how effective their current email solution is, as emails aren’t stopped by the SEG before reaching the provider – allowing for improved visibility from first deployment.
Darktrace works with email providers to take advantage of their native security and combine it with our Self-Learning AI, offering flexibility without compromising on speed of deployment. This approach enhances detection by leveraging the same API connections to gather additional context from other SaaS applications like Microsoft Teams and SharePoint – hardening defenses across the organization.
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
How email-delivered prompt injection attacks can target enterprise AI – and why it matters
Prompt injection is a newly emerging threat, with only a handful of confirmed victims so far – targeting how AI systems use data rather than exploiting traditional software vulnerabilities. As agentic AI becomes embedded across enterprise environments, attackers may attempt to manipulate these systems through hidden instructions in everyday email content.
Darktrace Unites Human Behavior and Threat Detection Across Email, Slack, Teams, and Zoom
Introducing the adaptive era of email security: a unified platform that connects personalized coaching, collaboration tools, and user behavior into a self-improving defense system.
Why Organizations are Moving to Label-free, Behavioral DLP for Outbound Email
Modern data loss doesn’t always look like a regex match. It can look like everyday communication slightly out of context. Here’s how a domain specific language model paired with behavioral learning protects labeled and unlabeled data without slowing business down.
When Trust Becomes the Attack Surface: Supply-Chain Attacks in an Era of Automation and Implicit Trust
Software supply-chain attacks in 2026
Software supply-chain attacks now represent the primary threat shaping the 2026 security landscape. Rather than relying on exploits at the perimeter, attackers are targeting the connective tissue of modern engineering environments: package managers, CI/CD automation, developer systems, and even the security tools organizations inherently trust.
These incidents are not isolated cases of poisoned code. They reflect a structural shift toward abusing trusted automation and identity at ecosystem scale, where compromise propagates through systems designed for speed, not scrutiny. Ephemeral build runners, regardless of provider, represent high‑trust, low‑visibility execution zones.
The Axios compromise and the cascading Trivy campaign illustrate how quickly this abuse can move once attacker activity enters build and delivery workflows. This blog provides an overview of the latest supply chain and security tool incidents with Darktrace telemetry and defensive actions to improve organizations defensive cyber posture.
1. Why the Axios Compromise Scaled
On 31 March 2026, attackers hijacked the npm account of Axios’s lead maintainer, publishing malicious versions 1.14.1 and 0.30.4 that silently pulled in a malicious dependency, plain‑crypto‑[email protected]. Axios is a popular HTTP client for node.js and processes 100 million weekly downloads and appears in around 80% of cloud and application environments, making this a high‑leverage breach [1].
The attack chain was simple yet effective:
A compromised maintainer account enabled legitimate‑looking malicious releases.
The poisoned dependency executed Remote Access Trojans (RATs) across Linux, macOS and Windows systems.
The malware beaconed to a remote command-and-control (C2) server every 60 seconds in a loop, awaiting further instructions.
The installer self‑cleaned by deleting malicious artifacts.
All of this matters because a single maintainer compromise was enough to project attacker access into thousands of trusted production environments without exploiting a single vulnerability.
A view from Darktrace
Multiple cases linked with the Axios compromise were identified across Darktrace’s customer base in March 2026, across both Darktrace / NETWORK and Darktrace / CLOUD deployments.
In one Darktrace / CLOUD deployment, an Azure Cloud Asset was observed establishing new external HTTP connectivity to the IP 142.11.206[.]73 on port 8000. Darktrace deemed this activity as highly anomalous for the device based on several factors, including the rarity of the endpoint across the network and the unusual combination of protocol and port for this asset. As a result, the triggering the "Anomalous Connection / Application Protocol on Uncommon Port" model was triggered in Darktrace / CLOUD. Detection was driven by environmental context rather than a known indicator at the time. Subsequent reporting later classified the destination as malicious in relation to the Axios supply‑chain compromise, reinforcing the gap that often exists between initial attacker activity and the availability of actionable intelligence. [5]
Additionally, shortly before this C2 connection, the device was observed communicating with various endpoints associated with the NPM package manager, further reinforcing the association with this attack.
Figure 1: Darktrace’s detection of the unusual external connection to 142.11[.]206[.]73 via port 8000.
Within Axios cases observed within Darktrace / NETWORK customer environments, activity generally focused on the use of newly observed cURL user agents in outbound connections to the C2 URL sfrclak[.]com/6202033, alongside the download of malicious files.
In other cases, Darktrace / NETWORK customers with Microsoft Defender for Endpoint integration received alerts flagging newly observed system executables and process launches associated with C2 communication.
Figure 2: A Security Integration Alert from Microsoft Defender for Endpoint associated with the Axios supply chain attack.
2. Why Trivy bypassed security tooling trust
Between late February and March 22, 2026, the threat group TeamPCP leveraged credentials from a previous incident to insert malicious artifacts across Trivy’s distribution ecosystem, including its CI automation, release binaries, Visual Studio Code extensions, and Docker container images [2].
While public reporting has emphasized GitHub Actions, Darktrace telemetry highlights attacker execution within CI/CD runner environments, including ephemeral build runners. These execution contexts are typically granted broad trust and limited visibility, allowing malicious activity within build automation to blend into expected operational workflows, regardless of provider.
This was a coordinated multi‑phase attack:
75 of 76 of trivy-action tags and all setup‑trivy tags were force‑pushed to deliver a malicious payload.
A malicious binary (v0.69.4) was distributed across all major distribution channels.
Developer machines were compromised, receiving a persistent backdoor and a self-propagating worm.
Secrets were exfiltrated at scale, including SSH keys, Kuberenetes tokens, database passwords, and cloud credentials across Amazon Web Service (AWS), Azure, and Google Cloud Platform (GCP).
Within Darktrace’s customer base, an AWS EC2 instance monitored by Darktrace / CLOUD appeared to have been impacted by the Trivy attack. On March 19, the device was seen connecting to the attacker-controlled C2 server scan[.]aquasecurtiy[.]org (45.148.10[.]212), triggering the model 'Anomalous Server Activity / Outgoing from Server’ in Darktrace / CLOUD.
Despite this limited historical context, Darktrace assessed this activity as suspicious due to the rarity of the destination endpoint across the wider deployment. This resulted in the triggering of a model alert and the generation of a Cyber AI Analyst incident to further analyze and correlate the attack activity.
TeamPCP’s continued abused of GitHub Actions against security and IT tooling has also been observed more recently in Darktrace’s customer base. On April 22, an AWS asset was seen connecting to the C2 endpoint audit.checkmarx[.]cx (94.154.172[.]43). The timing of this activity suggests a potential link to a malicious Bitwarden package distributed by the threat actor, which was only available for a short timeframe on April 22. [4][3]
Figure 3: A model alert flagging unusual external connectivity from the AWS asset, as seen in Darktrace / CLOUD .
While the Trivy activity originated within build automation, the underlying failure mode mirrors later intrusions observed via management tooling. In both cases, attackers leveraged platforms designed for scale and trust to execute actions that blended into normal operational noise until downstream effects became visible.
Quest KACE: Legacy Risk, Real Impact
The Quest KACE System Management Appliance (SMA) incident reinforces that software risk is not confined to development pipelines alone. High‑trust infrastructure and management platforms are increasingly leveraged by adversaries when left unpatched or exposed to the internet.
Throughout March 2026, attackers exploited CVE 2025-32975 to authentication on outdated, internet-facing KACE appliances, gaining administrative control and pushing remote payloads into enterprise environments. Organizations still running pre-patch versions effectively handed adversaries a turnkey foothold, reaffirming a simple strategic truth: legacy management systems are now part of the supply-chain threat surface, and treating them as “low-risk utilities” is no longer defensible [3].
Within the Darktrace customer base, a potential case was identified in mid-March involving an internet-facing server that exhibited the use of a new user agent alongside unusual file downloads and unexpected external connectivity. Darktrace identified the device downloading file downloads from "216.126.225[.]156/x", "216.126.225[.]156/ct.py" and "216.126.225[.]156/n", using the user agents, "curl/8.5.0" & "Python-urllib/3.9".
The timeframe and IoCs observed point towards likely exploitation of CVE‑2025‑32975. As with earlier incidents, the activity became visible through deviations in expected system behavior rather than through advance knowledge of exploitation or attacker infrastructure. The delay between observed exploitation and its addition to the Known Exploited Vulnerabilities (KEV) catalogue underscores a recurring failure: retrospective validation cannot keep pace with adversaries operating at automation speed.
The strategic pattern: Ecosystem‑scale adversaries
The Axios and Trivy compromises are not anomalies; they are signals of a structural shift in the threat landscape. In this post-trust era, the compromise of a single maintainer, repository token, or CI/CD tag can produce large-scale blast radiuses with downstream victims numbering in the thousands. Attackers are no longer just exploiting vulnerabilities; they are exploiting infrastructure privileges, developer trust relationships, and automated build systems that the industry has generally under secured.
Supply‑chain compromise should now be treated as an assumed breach scenario, not a specialized threat class, particularly across build, integration, and management infrastructure. Organizations must operate under the assumption that compromise will occur within trusted software and automation layers, not solely at the network edge or user endpoint. Defenders should therefore expect compromise to emerge from trusted automation layers before it is labelled, validated, or widely understood.
The future of supply‑chain defense lies in continuous behavioral visibility, autonomous detection across developer and build environments, and real‑time anomaly identification.
As AI increasingly shapes software development and security operations, defenders must assume adversaries will also operate with AI in the loop. The defensive edge will come not from predicting specific compromises, but from continuously interrogating behavior across environments humans can no longer feasibly monitor at scale.
Credit to Nathaniel Jones (VP, Security & AI Strategy, FCISCO), Emma Foulger (Global Threat Research Operations Lead), Justin Torres (Senior Cyber Analyst), Tara Gould (Malware Research Lead)
How email-delivered prompt injection attacks can target enterprise AI – and why it matters
What are email-delivered prompt injection attacks?
As organizations rapidly adopt AI assistants to improve productivity, a new class of cyber risk is emerging alongside them: email-delivered AI prompt injection. Unlike traditional attacks that target software vulnerabilities or rely on social engineering, this is the act of embedding malicious or manipulative instructions into content that an AI system will process as part of its normal workflow. Because modern AI tools are designed to ingest and reason over large volumes of data, including emails, documents, and chat histories, they can unintentionally treat hidden attacker-controlled text as legitimate input.
At Darktrace, our analysis has shown an increase of 90% in the number of customer deployments showing signals associated with potential prompt injection attempts since we began monitoring for this type of activity in late 2025. While it is not always possible to definitively attribute each instance, internal scoring systems designed to identify characteristics consistent with prompt injection have recorded a growing number of high-confidence matches. The upward trend suggests that attackers are actively experimenting with these techniques.
Recent examples of prompt injection attacks
Two early examples of this evolving threat are HashJack and ShadowLeak, which illustrate prompt injection in practice.
HashJack is a novel prompt injection technique discovered in November 2025 that exploits AI-powered web browsers and agentic AI browser assistants. By hiding malicious instructions within the URL fragment (after the # symbol) of a legitimate, trusted website, attackers can trick AI web assistants into performing malicious actions – potentially inserting phishing links, fake contact details, or misleading guidance directly into what appears to be a trusted AI-generated output.
ShadowLeak is a prompt injection method to exfiltrate PII identified in September 2025. This was a flaw in ChatGPT (now patched by OpenAI) which worked via an agent connected to email. If attackers sent the target an email containing a hidden prompt, the agent was tricked into leaking sensitive information to the attacker with no user action or visible UI.
What’s the risk of email-delivered prompt injection attacks?
Enterprise AI assistants often have complete visibility across emails, documents, and internal platforms. This means an attacker does not need to compromise credentials or move laterally through an environment. If successful, they can influence the AI to retrieve relevant information seamlessly, without the labor of compromise and privilege escalation.
The first risk is data exfiltration. In a prompt injection scenario, malicious instructions may be embedded within an ordinary email. As in the ShadowLeak attack, when AI processes that content as part of a legitimate task, it may interpret the hidden text as an instruction. This could result in the AI disclosing sensitive data, summarizing confidential communications, or exposing internal context that would otherwise require significant effort to obtain.
The second risk is agentic workflow poisoning. As AI systems take on more active roles, prompt injection can influence how they behave over time. An attacker could embed instructions that persist across interactions, such as causing the AI to include malicious links in responses or redirect users to untrusted resources. In this way, the attacker inserts themselves into the workflow, effectively acting as a man-in-the-middle within the AI system.
Why can’t other solutions catch email-delivered prompt injection attacks?
AI prompt injection challenges many of the assumptions that traditional email security is built on. It does not fit the usual patterns of phishing, where the goal is to trick a user into clicking a link or opening an attachment.
Most security solutions are designed to detect signals associated with user engagement: suspicious links, unusual attachments, or social engineering cues. Prompt injection avoids these indicators entirely, meaning there are fewer obvious red flags.
In this case, the intention is actually the opposite of user solicitation. The objective is simply for the email to be delivered and remain in the inbox, appearing benign and unremarkable. The malicious element is not something the recipient is expected to engage with, or even notice.
Detection is further complicated by the nature of the prompts themselves. Unlike known malware signatures or consistent phishing patterns, injected prompts can vary widely in structure and wording. This makes simple pattern-matching approaches, such as regex, unreliable. A broad rule set risks generating large numbers of false positives, while a narrow one is unlikely to capture the diversity of possible injections.
How does Darktrace catch these types of attacks?
The Darktrace approach to email security more generally is to look beyond individual indicators and assess context, which also applies here.
For example, our prompt density score identifies clusters of prompt-like language within an email rather than just single occurrences. Instead of treating the presence of a phrase as a blocking signal, the focus is on whether there is an unusual concentration of these patterns in a way that suggests injection. Additional weighting can be applied where there are signs of obfuscation. For example, text that is hidden from the user – such as white font or font size zero – but still readable by AI systems can indicate an attempt to conceal malicious prompts.
This is combined with broader behavioral signals. The same communication context used to detect other threats remains relevant, such as whether the content is unusual for the recipient or deviates from normal patterns.
Ask your email provider about email-delivered AI prompt injection
Prompt injection targets not just employees, but the AI systems they rely on, so security approaches need to account for both.
Though there are clear indications of emerging activity, it remains to be seen how popular prompt injection will be with attackers going forward. Still, considering the potential impact of this attack type, it’s worth checking if this risk has been considered by your email security provider.
Questions to ask your email security provider
What safeguards are in place to prevent emails from influencing AI‑driven workflows over time?
How do you assess email content that’s benign for a human reader, but may carry hidden instructions intended for AI systems?
If an email contains no links, no attachments, and no social engineering cues, what signals would your platform use to identify malicious intent?