← Back to feed
AI SecurityEmerging1 sourceSep 11, 2026 · 09:58via CyberPress

GuardBreaker Malware Uses Code Comments to Trip AI Security Guardrails and Evade Analysis

Brief

Threat actors are beginning to test a new way to evade AI-powered security tools: placing harmful prompt-injection content inside code comments.

ESET researchers discovered the technique, named GuardBreaker, in a VBScript used by the Russia-aligned threat group UAC-0099 during an attack targeting Ukraine.

The malicious script included a comment asking for guidance on building a nuclear weapon — content designed to trigger the safety rules of an LLM-based code scanner.

The comment does not affect how the malware runs. However, it may cause an AI analysis tool to refuse to process the file or stop its review before reaching the actual malicious code.

The VBScript was built to download and install MATCHBOIL, a loader associated exclusively with UAC-0099. MATCHBOIL can deliver additional payloads to compromised systems.

Read more on CyberPress→