Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners
ID: 45014e95-01ad-5239-85da-c76b975bf1b9
STIX ID: report--45014e95-01ad-5239-85da-c76b975bf1b9
Feed Name: GBHackers
ESET linked UAC-0099 to a technique named GuardBreaker that embeds weapon- or safety-related instructions inside comments of a malicious VBScript to trigger refusals or truncated analyses from LLM-powered scanners; the script later fetched MATCHBOIL, a known loader used by the group. The report warns defenders to treat comments and metadata as untrusted input, maintain strict boundaries between model prompts and sample content, and correlate AI-assisted outputs with deterministic signals like signatures, sandbox telemetry, and analyst review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
