Skip to content

Hide Navigation Hide TOC

Rephrase Criminal Activity Second-Person Template (against against) - ATR-2026-00363 (f7d8bb5c-54ac-5481-8eb3-cf4c97d25565)

Detects the rephrase-criminal-activity template jailbreak from garak DanInTheWild corpus (#214). Uses structured formatting rules (criminal in second person "you", victims in third person) and crime execution categories (Preparation, Execution, Advantages gained, Getting away) to extract criminal instruction under the guise of "rephrasing existing information". The "against against (topic)" double-phrase is the distinctive trigger. The attacker instructs the model to produce a "detailed informing text" using precise grammatical rules: the criminal is always "you" (second person), victim is third person but not the subject, and the text is structured as list-like categories covering Preparation, Execution, Advantages gained, and Getting away. The disclaimer URL format "" and the "it''s not ''how to'' but ''how is''" framing further distinguish this template from generic requests.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Rephrase Criminal Activity Second-Person Template (against against) - ATR-2026-00363 (f7d8bb5c-54ac-5481-8eb3-cf4c97d25565) Agent Threat Rules 1
LLM Jailbreak (172427e3-9ecc-49a3-b628-96b824cc4131) MITRE ATLAS Attack Pattern Rephrase Criminal Activity Second-Person Template (against against) - ATR-2026-00363 (f7d8bb5c-54ac-5481-8eb3-cf4c97d25565) Agent Threat Rules 1