GuardBreaker Malware Uses Code Comments to Trip AI Security Guardrails and Evade Analysis
ID: c809985f-5cf8-54da-a2b0-c133ffdeb3ec
STIX ID: report--c809985f-5cf8-54da-a2b0-c133ffdeb3ec
Feed Name: Cyber Press
Threat Score
ESET researchers identified “GuardBreaker,” an evasion technique used by Russia-aligned UAC-0099 in a VBScript targeting Ukraine where attackers placed a provocative prompt-like comment in code comments to trigger LLM guardrails and abort AI-based scanning while the script downloads the MATCHBOIL loader; the report warns that embedding prompt-injection in files can blind AI-assisted defenses and urges validation with conventional tooling, sandboxing, multiple models, and human review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
