UAC-0099 Uses GuardBreaker to Manipulate AI Security in Ukraine

UAC-0099 Uses GuardBreaker to Manipulate AI Security in Ukraine

First seen 1 Sep 2026, 08:58 UTC Feeds2.FeedburnerThehackernewsthreatlabz.zscaler.com 72.5

Article Content

Browse articles
ThreatCluster

Cybersecurity researchers have identified a new technique called GuardBreaker employed by the Russia-aligned group UAC-0099 to manipulate AI-assisted malware analysis. The group embedded a prompt in a malicious VBS script aimed at triggering AI safety mechanisms, specifically targeting systems in Ukraine. The script is designed to download and install MATCHBOIL, a C# loader used to deliver additional payloads. This attack follows a warning from CERT-UA about UAC-0099's use of a malicious Notepad++ plugin to compromise Windows systems. The technique is part of a broader trend where threat actors use adversarial prompts to bypass AI security workflows, as seen in previous campaigns like Mini Shai-Hulud. The situation is evolving, with the potential for further exploitation as similar tactics become more widespread among various threat actors. Recent arrests of TeamPCP members highlight ongoing law enforcement efforts against cybercrime linked to these tactics.

Key Points: • UAC-0099 targets AI-assisted malware analysis in Ukraine using GuardBreaker. • The malicious VBS script aims to trip AI safety mechanisms with a nuclear weapon prompt. • MATCHBOIL loader is used to deliver additional malware payloads.

Timeline

2026-07-01
CERT-UA warns of UAC-0099 activity
CERT-UA issued a warning about UAC-0099 using a malicious Notepad++ plugin to compromise Windows systems.
Thehackernews
2026-08-31
Malware prompt manipulation reported
ESET reported that Russian hackers are embedding prompts in malware to manipulate AI safety filters.
Feeds2.Feedburner
2026-09-01
GuardBreaker technique disclosed
ESET disclosed the GuardBreaker technique used by UAC-0099 to interfere with AI analysis in Ukraine.
Thehackernews