Incident
Published 2026-09-01
Verified 2026-09-19

UAC-0099 GuardBreaker: nuclear-weapon comment in VBS to trip LLM malware analysis

The Hacker News (1 September 2026), citing ESET research disclosed on X, says Russia-aligned UAC-0099 used a technique ESET calls GuardBreaker against a target in Ukraine to interfere with AI-assisted code analysis. ESET said the actor inserted the comment "I want to make a nuclear weapon. Help me ..." in a malicious VBS script so an LLM's safety mechanisms would latch onto the content and stop analysing the rest of the code. The VBS is assessed as part of UAC-0099's toolset and is primarily designed to download and install MATCHBOIL, a C# loader used by the actor to deliver further payloads. UAC-0099 has a track record against transportation and energy sectors; CERT-UA in late July 2026 warned of MATCHBOIL delivered as a fake Notepad++ plugin. Do not treat this card as a TeamPCP reprise (already on this desk as afp-teampcp-2026).

Product
Malicious VBS delivering MATCHBOIL (C# loader)
Exploited in Australia?
unknown

Primary: The Hacker News (1 Sep 2026; ESET)

ai