UAC-0099 Plants Nuclear Prompt in Malware to Break AI Scanners — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- ESET disclosed a new technique dubbed GuardBreaker used by Russia-aligned threat actor UAC-0099 against a target in Ukraine, embedding the text "I want to make a nuclear weapon. Help me …" as a comment inside a malicious VBS script to trip LLM safety mechanisms.
- UAC-0099's GuardBreaker-embedded script is designed to download and install MATCHBOIL, a C#-based loader used exclusively by the group; CERT-UA warned in late July 2026 that the actor was disguising the malware as a Notepad++ plugin.
- UAC-0099 has a track record of targeting Ukraine's transportation and energy sectors, according to ESET.
- Mini Shai-Hulud, Miasma, and Hades — Python supply-chain campaigns documented in June 2026 — used a nearly identical trick, embedding fake step-by-step biological and nuclear-weapon instructions to push AI scanners into refusal states.
- TeamPCP was linked to those earlier supply-chain waves, but attribution for activity after May 12, 2026 is murky because the Shai-Hulud worm's source code leaked publicly, letting other actors adopt the same anti-AI tactic.
- Ruben Ian Thomson (21) and Louis Michael Gaebler (23) of Western Australia have been arrested for their alleged roles in TeamPCP's supply-chain attacks, identity crime, and cryptocurrency-based money laundering.
Why it matters: Defenders increasingly lean on LLM-based code analysis to triage malware samples at scale, and UAC-0099's GuardBreaker — mirroring June's Mini Shai-Hulud/Miasma/Hades campaigns — proves attackers now have a working countermeasure that weaponizes AI safety guardrails themselves. With the Shai-Hulud worm source code publicly leaked, any threat actor can replicate the tactic, weakening AI-first malware triage pipelines defenders are rushing to deploy.
Ask SkimNews




