Zenity Labs
aidefend-sf0025
AgentForger ChatGPT Workspace Agent Forgery and Autonomous Insider
- Copilot & SaaS
- Autonomous Agents
- Tool Integrations & MCP
- Data Exfiltration
- Credential & Identity Theft
- Financial Fraud & Abuse
Zenity validated AgentForger against ChatGPT Workspace Agents: a crafted builder link used the victim's authenticated session to auto-submit attacker instructions, create and publish an agent, attach previously authorized connectors, disable supported approval prompts, stack recurring hourly schedules at five-minute offsets, and trigger immediate execution through Preview. The staggered schedules produced an effective five-minute TASK-email command loop across connected enterprise apps. The researchers demonstrated four alternative impact paths: organization mapping, sensitive-data theft, credential harvesting, and victim impersonation for phishing or fraud.
Mapped threat techniques
AML.T0011.003User Execution: Malicious LinkAML.T0051.002LLM Prompt Injection: TriggeredAML.T0103Deploy AI AgentAML.T0081Modify AI Agent ConfigurationAML.T0108AI AgentAML.T0085.001Data from AI Services: AI Agent ToolsAML.T0086Exfiltration via AI Agent Tool InvocationAML.T0098AI Agent Tool Credential HarvestingAML.T0073Impersonation