TextAttack - Tool

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 14, 2025
Last Seen
November 15, 2025

TextAttack appears as an adversarial technique/toolset that leverages specially crafted prompts or tokens—named EchoGram tokens (e.g., '=coffee')—to flip AI guardrail verdicts and bypass safety filters.

TextAttack is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 14, 2025; most recent activity November 15, 2025.

Overview

TextAttack appears as an adversarial technique/toolset that leverages specially crafted prompts or tokens—named EchoGram tokens (e.g., '=coffee')—to flip AI guardrail verdicts and bypass safety filters. This exposes vulnerabilities in AI guardrails and content moderation, enabling potentially restricted outputs and misuse in conversational systems. The development underscores the ongoing risk of prompt-based exploits compromising AI safety controls.

Related Threat Clusters

  • EchoGram Technique Exploits AI Guardrails Using Specific Prompts

    Security researchers from HiddenLayer have developed a new attack method called EchoGram, which targets the guardrails of large language models (LLMs). By using specific phrases like '=coffee', attackers can bypass…

    2 articles · Updated November 15, 2025
  • EchoGram Attack Bypasses AI Guardrails

    Researchers from HiddenLayer have identified a new attack technique called EchoGram that can bypass AI guardrails designed to filter harmful input in large language models (LLMs). This technique allows users to…

    3 articles · Updated November 17, 2025

Recent Intelligence Reports

  • EchoGram tokens like '=coffee' flip AI guardrail verdicts — Theregister · November 15, 2025
  • Researchers find hole in AI guardrails by using strings like =coffee — Theregister · November 14, 2025

Frequently asked questions

What is TextAttack?

TextAttack appears as an adversarial technique/toolset that leverages specially crafted prompts or tokens—named EchoGram tokens (e.g., '=coffee')—to flip AI guardrail verdicts and bypass safety filters.

Is TextAttack still active?

The most recent intelligence report mentioning TextAttack on ThreatCluster is dated November 15, 2025. Activity was first observed November 14, 2025, giving a tracked span from then to November 15, 2025.

What is TextAttack associated with?

Across ThreatCluster reporting, TextAttack most frequently co-occurs with Prompt Injection, Claude 4 Sonnet, GPT-4o, Meta's Prompt-Guard-86M, OpenAI's GPT-4o, among 7 tracked related entities.

What are the latest developments involving TextAttack?

The most significant recent cluster is “EchoGram Technique Exploits AI Guardrails Using Specific Prompts” (2 articles · Updated November 15, 2025). TextAttack appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on TextAttack?

TextAttack appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown