DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

UAC-0099 GuardBreaker Trips LLM Safety to Block Malware Analysis

Forensic Summary

Russia-aligned threat actor UAC-0099 has deployed a technique called GuardBreaker that embeds nuclear weapon prompts inside malicious VBS scripts to deliberately trigger LLM safety guardrails and prevent AI-assisted malware analysis. This represents a maturing offensive tradecraft where adversarial prompt injection is weaponised not to extract information but to induce refusal states in AI security tooling. The technique mirrors similar tactics observed in the TeamPCP supply chain campaigns, signalling that LLM-first security pipelines are becoming a recognised and actively exploited weak point.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/uac-0099-guardbreaker-trips-llm-safety-to-block-malware-analysis/

Top comments (0)