DEV Community

Mark0
Mark0

Posted on

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Cybersecurity researchers have identified a new anti-analysis technique named GuardBreaker, attributed to the Russia-aligned threat actor UAC-0099. This method involves embedding adversarial prompts, such as requests for nuclear weapon instructions, within malicious scripts to intentionally trigger the safety mechanisms of Large Language Models (LLMs) used in security triage. By forcing these AI models into a refusal state, attackers effectively blind AI-assisted analysis tools to the rest of the malicious payload.

The GuardBreaker technique has been observed in VBS scripts used to deliver the MATCHBOIL loader, targeting infrastructure in Ukraine. This development follows a growing trend of 'anti-AI' tactics previously seen in supply chain attacks by groups like TeamPCP. These incidents highlight the evolving battlefield of security automation, where threat actors exploit the inherent safety guardrails of AI scanners to bypass detection in build pipelines and developer environments.


Read Full Article

Top comments (0)