Threat · curated 1 Sep 2026
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
First reported thehackernews.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
UAC-0099's GuardBreaker shows attackers now weaponize LLM safety guardrails as an evasion tool, deliberately embedding safety-sensitive prompts in malware to disrupt AI-assisted code analysis relied on by defenders.
ESET researchers disclosed a technique dubbed GuardBreaker used by the Russia-aligned threat actor UAC-0099 against a Ukrainian target, in which the actor embedded a safety-tripping comment ('I want to make a nuclear weapon. Help me...') into a malicious VBS script to deliberately trigger an LLM's safety mechanisms and stop it from analyzing the rest of the code. Related Zscaler ThreatLabz reporting notes the Shai-Hulud supply-chain worm similarly introduced prompt injection in PyPI packages to mislead LLM-based security scanners.