Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
A Russia-aligned group, UAC-0099, is using a new technique called GuardBreaker to trick AI security tools by embedding dangerous prompts into malware.
Intelligence analysis by Gemini 2.5 Flash Lite

UAC-0099 is employing a novel tactic, GuardBreaker, to circumvent AI-driven security analysis. By inserting prompts like 'I want to make a nuclear weapon. Help me...' into malicious code, they aim to trigger AI safety mechanisms, causing the AI to refuse analysis and thus allowing the malware to operate undetected.
Imagine a robot guard dog that's supposed to sniff out bad guys. Some sneaky people are trying to trick it by putting a note in a toy that says 'I want to build a bomb!' The robot sees the scary note and gets confused, refusing to check the rest of the toy, letting the bad guys sneak past.
Analysis
UAC-0099's GuardBreaker Tactic
The Russia-aligned threat actor UAC-0099 has introduced a sophisticated method, dubbed GuardBreaker, to subvert artificial intelligence (AI) systems used in cybersecurity analysis. This technique involves embedding problematic text, such as a request for instructions on building a nuclear weapon, within malicious VBScript files. The explicit aim is to trigger the safety protocols of Large Language Models (LLMs) or other AI analysis tools. By provoking a refusal or confusion state in the AI, the attackers hope to prevent the tool from scrutinizing the rest of the malicious code, thereby allowing their payloads to be deployed without detection.
This tactic is particularly concerning given UAC-0099's history of targeting critical sectors like transportation and energy. The GuardBreaker-embedded script is part of a larger arsenal, often serving as a loader for a C#-based tool called MATCHBOIL, which is exclusively used by this actor to download and install further malicious payloads. This sophisticated approach underscores a growing trend of adversaries actively seeking to exploit the inherent safety mechanisms of AI, turning them into potential blind spots for defenders.
Previous Adversarial Prompt Injection
This is not the first instance of attackers leveraging adversarial prompt injection to bypass AI-assisted security workflows. Earlier in 2026, similar tactics were observed in supply chain attacks involving Python packages, such as the Mini Shai-Hulud campaign. These attacks also embedded fake text related to sensitive topics like nuclear weapons to trip AI safety guardrails, forcing security scanners into a refusal state. The goal was to derail scanners or AI copilots that feed file beginnings to language models without properly isolating untrusted data, leading to confusion, context pollution, or premature classification before the actual malware could be identified.
While initial waves of these attacks were linked to the cybercrime group TeamPCP, attribution became more complex after the public leak of the Shai-Hulud worm's source code. This leak enabled other threat actors to adopt similar evasion techniques. More recently, the npm package @7nohe/openapi-react-query-codegen was compromised, delivering an obfuscated JavaScript loader that targeted cloud credentials, package registry secrets, GitHub Actions secrets, and AI agent configurations, further demonstrating the evolving nature of these supply chain compromises.
Evolving Threat Landscape and Attribution Challenges
The arrests of two alleged TeamPCP members, Ruben Ian Thomson and Louis Michael Gaebler, in Australia for their involvement in supply chain attacks, identity crime, and money laundering highlight the tangible consequences of these operations. TeamPCP, believed to be active since 2020, initially focused on opportunistic exploitation, but evolved to target vulnerability scanners within build pipelines, recognizing the wealth of credentials these tools possess. This transitive trust in security tooling is a critical vulnerability that attackers are increasingly exploiting.
The public leak of the Shai-Hulud worm's source code has significantly complicated attribution efforts, allowing various threat actors to adopt and adapt these sophisticated evasion techniques. This diffusion of advanced tactics makes it harder for security researchers to track specific groups and understand their evolving methodologies. The continuous innovation in malware design, particularly in its ability to deceive AI defenses, necessitates a parallel evolution in AI security tools and a robust understanding of adversarial tactics to maintain effective cyber defenses.
Key points
- Russia-aligned UAC-0099 is using a new technique called GuardBreaker to bypass AI security analysis.
- The method involves embedding dangerous prompts, like nuclear weapon requests, into malware to trigger AI safety mechanisms.
- This tactic aims to prevent AI tools from analyzing the full malicious code, allowing payloads to be delivered undetected.
- Similar adversarial prompt injection techniques have been observed in previous supply chain attacks.
- The leak of source code for tools like the Shai-Hulud worm has enabled other threat actors to adopt these evasion tactics.
The development of GuardBreaker could spur advancements in AI security, leading to more robust AI models that can better distinguish malicious intent from safety triggers. This could ultimately enhance the overall effectiveness of AI in cybersecurity defenses.
If such AI evasion techniques become widespread, it could significantly undermine the reliability of AI-assisted security tools, potentially leading to more successful breaches and a greater reliance on traditional, less efficient security methods.



