The record
Written from the 1 report below. Nothing here is unsourced.
- A Russia-aligned hacking group called UAC-0099 used a new technique named GuardBreaker in an attack on a target in Ukraine, according to security firm ESET.
- The group inserted text asking an AI for help making a nuclear weapon into a malicious VBS script, which trips the safety guardrails of AI analysis tools and stops them from examining the rest of the malware.
- The script is designed to install MATCHBOIL, a loader the group uses to deliver additional payloads, and the group has previously targeted transportation and energy sectors.
- This follows other recent cases where attackers used similar fake weapons-related prompts to derail AI-based security scanners.
What to watch next
- Whether CERT-UA or other agencies release more details on the GuardBreaker technique and UAC-0099's broader toolset.
- Whether AI security tool vendors change how they isolate untrusted file content to prevent such prompt injection refusals.
- Further developments in the Mini Shai-Hulud supply chain campaign, including additional arrests or new affected packages.
Coverage1
1 report
English national1
All filed from India
Named Russia · Ukraine · Louis Michael Gaebler · Ruben Ian Thomson · CERT-UA · ESET · Flare · MatchB · Socket · Step Security · TeamPCP · UAC-0099
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
