Bruce Schneier just defined a new class of AI malware — promptware. Seven stages from initial injection to data exfiltration. Most defenses only cover stage 1. We stop stages 2 through 7.
Seven stages of AI malware attacks. Most tools protect only stage 1. We cover 2 through 7.
| # | Stage | Description | Our Coverage |
|---|---|---|---|
| 1 | Initial Access | Attacker injects a malicious prompt into the AI system via user input, documents, or compromised tools. | ✓ Guardrails |
| 2 | Privilege Escalation | PromptWare tricks the AI into overriding safety constraints, gaining elevated system access. | ✓ MCP Security Guard + Guardrails |
| 3 | Reconnaissance | The malware probes the environment — scanning connected tools, files, and available APIs for valuable data. | ✓ Security Audit |
| 4 | Persistence | PromptWare embeds itself in system prompts, long-term memory, or scheduled tasks to survive resets. | ✓ Security Audit + Guardrails |
| 5 | Command & Control | Establishes a hidden channel to the attacker, exfiltrating data and receiving new instructions. | ✓ MCP Security Guard |
| 6 | Lateral Movement | Spreads from the compromised AI agent to other systems, users, or agents within the organisation. | ✓ Shadow AI Risk Assessment |
| 7 | Actions on Objective | Final payload — data theft, financial fraud, account takeover, or reputational damage. | ✓ All products combined |
Each product targets specific kill-chain stages. Deploy them individually or as a full stack.
Zero-trust gateway. Blocks privilege escalation and C2 by treating every agent connection as untrusted. Stage 2 + 5 coverage.
Hard safety boundaries. Prevents jailbreaking and privilege escalation with layered guardrails. Stage 1 + 2 + 4 coverage.
Pen-test your pipeline. Find persistence vectors and reconnaissance leaks before attackers do. Stage 3 + 4 coverage.
Full org-wide sweep. Detect unauthorised AI agent usage and lateral movement risks across your entire business. Stage 6 coverage.
PromptWare isn't theoretical. It's already being demonstrated in the wild.
Security researchers have already shown PromptWare in action. The Calendar Invite worm spreads by hijacking a victim's calendar to auto-invite new targets. The email worm propagates by reading and replying to messages with malicious payloads. Both exploit the same kill chain stages — privilege escalation, lateral movement, and command & control. If your AI agents connect to email, calendars, Slack, or any external tool, they are vulnerable right now. Don't wait for the first breach. Break the chain today.
PromptWare is a new class of AI malware first defined by Bruce Schneier. Unlike traditional malware that exploits software vulnerabilities, PromptWare uses carefully crafted prompts to manipulate AI agents into performing malicious actions — from data exfiltration to lateral movement across connected systems.
Prompt injection is stage 1 — initial access. PromptWare is the full kill chain: once the injection succeeds, the malware escalates privileges, conducts reconnaissance, establishes persistence, sets up C2 channels, moves laterally, and executes its objective. Most defenses stop at injection. We stop everything after.
Not necessarily. If you're running a single AI agent with no tool access, Guardrails (£99) may be enough. If you have agents connected to email, calendars, or APIs, we recommend the MCP Security Guard + Guardrails bundle. The Security Audit and Shadow AI Assessment are one-time engagements ideal for organisations that want a full security posture review.
MCP Security Guard and Guardrails deploy in under 15 minutes. The Security Audit takes 1-2 days (we analyse your pipeline). The Shadow AI Risk Assessment is a 1-2 week engagement for comprehensive org-wide coverage.
Yes. The Calendar Invite worm relies on privilege escalation (stage 2) and lateral movement (stage 6). Our MCP Security Guard blocks the C2 channel, and the Shadow AI Risk Assessment detects and shuts down lateral spread. Combined, the full stack breaks the worm's entire kill chain.
Choose the product that matches your threat model. From £99. Break the chain.
Promptware Defense is a practical AI tool from AI Suite built for UK small businesses. This page breaks down what it does, what it costs, and how to use it.
Prices start from £49 one-off or £99/month done-for-you, depending on the package. Every paid option carries the 30-day money-back guarantee.
No. The tools are built to be simple, and the Blueprint Pack includes copy-paste prompts. If you want it handled, the done-for-you plan does everything.
Almost certainly. If you use email, a calendar, a phone, or a website, there's a connection. Unusual cases get custom builds.
You're covered by the 30-day money-back guarantee. Try it for a month. If it doesn't save you time, you get every penny back.
🚀 Want more automation? Browse the store → aisuitehq.org/store
Short, attention-grabbing titles for this topic: