Cybersecurity researchers have identified a new technique known as GuardBreaker that is being used by the Russia aligned threat actor UAC 0099 to interfere with artificial intelligence assisted malware analysis. According to ESET, the technique was observed during an attack targeting an organization in Ukraine and is designed to trigger the safety mechanisms of large language models, preventing them from properly analyzing malicious code. Researchers found that the attackers inserted a comment containing a request about building a nuclear weapon into a malicious Visual Basic Script. Rather than serving any functional purpose within the malware, the text was intended to capture the attention of AI systems and activate their safety restrictions, causing them to stop analyzing the remainder of the script. ESET said the malicious script forms part of a broader toolset used by UAC 0099, a threat actor known for targeting the transportation and energy sectors.
The Visual Basic Script is primarily designed to download and install MATCHBOIL, a C sharp based loader that has been exclusively associated with UAC 0099 operations. Researchers noted that the threat actor has previously relied on MATCHBOIL to deliver additional malicious payloads to compromised systems. In July 2026, Computer Emergency Response Team of Ukraine, also known as CERT UA, warned that the group was distributing a malicious application disguised as a Notepad plus plus plugin to infect Windows systems with an updated version of MATCHBOIL. According to the latest findings, the addition of the GuardBreaker prompt represents an effort to disrupt AI assisted security workflows by exploiting the content moderation mechanisms built into modern language models rather than attempting to evade traditional antivirus detection methods.
Researchers also noted that this is not the first example of attackers attempting to interfere with AI based security analysis. Earlier in 2026, security researchers identified multiple Python packages associated with the Mini Shai Hulud, Miasma and Hades supply chain campaigns that contained similar prompt injection techniques. Those packages embedded misleading text related to biological and nuclear weapons in an effort to activate AI safety guardrails and prevent automated security tools from reaching the actual malicious code. Security researchers explained that when AI powered scanners process the beginning of a file without clearly separating trusted and untrusted content, they can enter a refusal state, become confused by the injected prompt or prematurely classify the file before completing a full analysis. Such techniques demonstrate how attackers are adapting their methods to exploit the growing use of AI assisted security tools within software development and malware analysis environments.
The research also highlighted the continuing evolution of software supply chain attacks. Recent investigations by Socket and Step Security uncovered another Mini Shai Hulud related compromise affecting an npm package that delivered an obfuscated JavaScript loader capable of downloading a second stage information stealer targeting cloud credentials, package registry credentials, GitHub Actions secrets and AI agent configuration data. Researchers noted that attribution for some of the activity following the public release of the Shai Hulud source code remains uncertain because multiple threat actors may now be using similar techniques. The findings emphasize the importance of treating AI generated analysis as one element of a broader security process while ensuring that automated tools are designed to distinguish between malicious prompt injections and executable code when analyzing suspicious files.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.