UAC-0099 Uses GuardBreaker to Evade AI Malware Detection

UAC-0099 Uses GuardBreaker to Evade AI Malware Detection

First seen 1 Sep 2026, 08:58 UTC Feeds2.FeedburnerThehackernewsCybernewsthreatlabz.zscaler.com 77.7

Article Content

Browse articles
ThreatCluster

Russian-linked hackers from the group UAC-0099 have developed a new technique called GuardBreaker to evade AI-assisted malware analysis. This method involves embedding a nuclear weapon prompt in malicious VBS scripts, which distracts AI systems from analyzing the actual malware code. The script is designed to download and install MATCHBOIL, a loader used exclusively by UAC-0099 to deliver additional payloads. The attack primarily targets Ukrainian organizations, particularly in the transportation and energy sectors. ESET, a Slovak cybersecurity firm, reported this technique and linked it to UAC-0099's ongoing operations. The Computer Emergency Response Team of Ukraine (CERT-UA) has documented similar tactics used by the group, highlighting their evolving methods. This incident underscores the growing sophistication of cyber threats leveraging AI manipulation.

Key Points: • UAC-0099 uses GuardBreaker to evade AI detection. • Malicious VBS scripts contain prompts to distract AI systems. • Targets include Ukrainian organizations in critical sectors.

Ask AI about this cluster

Timeline

2026-07-01
CERT-UA warns of UAC-0099 activity
CERT-UA documented changes in UAC-0099's tactics, including the use of malicious VBS files disguised as Notepad++ plugins.
Cybernews
2026-08-31
ESET reports GuardBreaker technique
ESET disclosed UAC-0099's use of GuardBreaker to evade AI malware analysis, embedding a nuclear prompt in VBS scripts.
Feeds2.Feedburner
Recent
UAC-0099 targets Ukrainian sectors
UAC-0099 has been actively targeting organizations in Ukraine's transportation and energy sectors with evolving malware techniques.
Thehackernews