logo

GuardBreaker Malware Uses Code Comments to Trip AI Security Guardrails and Evade Analysis

ID: c809985f-5cf8-54da-a2b0-c133ffdeb3ec

STIX ID: report--c809985f-5cf8-54da-a2b0-c133ffdeb3ec

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Varshini

...
...

ESET researchers identified “GuardBreaker,” an evasion technique used by Russia-aligned UAC-0099 in a VBScript targeting Ukraine where attackers placed a provocative prompt-like comment in code comments to trigger LLM guardrails and abort AI-based scanning while the script downloads the MATCHBOIL loader; the report warns that embedding prompt-injection in files can blind AI-assisted defenses and urges validation with conventional tooling, sandboxing, multiple models, and human review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.