Researchers say Russia-aligned hackers deploy a technique called “GuardBreaker” to interfere with AI-assisted analysis of malware targeting Ukraine. ESET reports the method is used by a threat actor tracked as UAC-0099, embedding a manipulative prompt into malicious code designed to trigger safety mechanisms in large language models (LLMs) and limit analysis output.
According to ESET, the GuardBreaker content appears in a Visual Basic Script (VBS) associated with UAC-0099. ESET characterizes the embedded prompt as styled like a nuclear-weapon-related instruction, placed as comments within the VBS script. The stated objective is to make automated or AI-supported tools less effective at processing or describing the malware during review.
Help Net Security and The Hacker News both frame the disclosure as an effort to “trip” AI guardrails during malware analysis. Both cite ESET’s findings and link the technique to UAC-0099’s activity in Ukraine, but primarily differ in emphasis: one focuses on the novelty of the technique and AI disruption, while the other highlights the nuclear-weapon prompt aspect and how it appears in the script.