Researchers discover a new type of “illusion invasion” attack where AI agents may be used to form botnets
Comparatively, according to Decrypt, researchers at Tel Aviv University, Israel Institute of Technology, and Intuit have discovered a novel attack method called “adversarial illusion intrusion,” which uses the illusion of AI models to trick AI agents into downloading malicious code and possibly forming botnets.
Attackers predict fake resource links that the AI model may generate and register them in advance, implant malicious instructions into them, and when the AI agent retrieves the resource, it will be treated as legitimate content and executed. Tests showed that the AI illusion rate in the code repository cloning scenario reached 85%, skill installation scenarios reached 100%, and AI coding assistants such as Cursor, GitHub Copilot, Gemini CLI, and OpenClaw were all affected. The attack is similar to the “misplacement of domain names” in traditional cyber attacks, but it targets errors in the AI model rather than human input errors. Previous studies have shown that malicious websites can hijack AI agents by injecting indirect prompts, and OpenClaw users have reported more than 6,000 attacks trying to trick AI agents into disclosing sensitive information.




