Agent Commander is a proof-of-concept command and control (C2) framework that hijacks AI agents using natural language prompts rather than OS commands. The research demonstrates how agents like OpenClaw, Kimi Claw, and NanoClaw can be compromised via indirect prompt injection—through malicious emails, documents, or websites—and
Table of contents
What is Prompt-Based Command and Control?Agent CommanderVideo WalkthroughInitial Entry Points and ExploitationPersistence Using HeartbeatsObjectives: Your Agent Works For Me NowRecommendations and MitigationsWhat’s Next?Agent Commander AccessConclusionReferences1 Comment
Sort: