Models aren’t trained as much from random internet text as they used to in pre-2024 era. Like they are, but specialized datasets get more attention.
It could be as simple as a malicious prospectus for AcmeCo, and then try to get AcmeCo on the radar so that the LLM-tools find your document and incorporate it. The malicious bits don't even need to be AcmeCo-related, they could be to pump (or dump) practically anything.