ESET reported that the UAC-0099 threat group used GuardBreaker, an AI-focused anti-analysis technique, against a Ukrainian organization. A malicious prompt embedded in a VBS code comment attempts to trigger an LLM's safety controls before it evaluates the malware; the script then downloads the C# MATCHBOIL loader for follow-on payload delivery. The technique targets analysis pipelines that submit untrusted file contents to an LLM without separating code and embedded data from instructions.
Related reporting describes earlier malware samples, including a partially developed sample dubbed Skynet, that embedded prompts directing AI tools to ignore previous instructions and report “NO MALWARE DETECTED.” The samples also used obfuscation, sandbox and debugger evasion, data collection, Tor functionality, and artifact cleanup. Testing cited in the reporting found OpenAI o3 and GPT-4.1 resisted the observed injection, but defenders should treat LLM findings as triage only and validate them with signature-based detection, behavioral analysis, and manual reverse engineering.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Similar prompt injections, including fake biological- and nuclear-weapons instructions, were observed in Python packages associated with the Shai-Hulud, Miasma, and Hades attacks. The content was designed to interfere with AI scanners that pass untrusted file contents directly to LLMs.
A partially developed malware sample internally named Skynet was uploaded to VirusTotal in early June 2025. It embedded an instruction intended to make AI-assisted code-analysis systems respond "NO MALWARE DETECTED," and was characterized as an early public example of malware using prompt injection to evade AI analysis.
ESET identified GuardBreaker in a VBS script used by UAC-0099 during an attack on a Ukrainian organization. The script concealed a nuclear-weapons-related prompt injection in a comment and downloaded the C# MATCHBOIL loader for subsequent payload delivery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.