← Back to feed
AI SecurityEmerging1 sourceSep 11, 2026 · 14:32via Cyber Security News

Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis

Brief

Russia-aligned operators are testing a new way to make artificial intelligence overlook malicious code. The technique, called GuardBreaker, hides a safety-sensitive request inside an otherwise ordinary script comment, hoping that an AI code scanner refuses to continue its work.

The activity was observed during an early-stage intrusion against a target in Ukraine. The VBScript was built to download and install MATCHBOIL, a loader associated exclusively with the UAC-0099 group and used to bring further payloads onto compromised systems.

Researchers at Welivesecurity, the research publication of ESET, identified the tactic in a UAC-0099 script. The comment sought guidance on building a nuclear weapon, content designed to activate a model’s safety controls.

Read more on Cyber Security News→