Pro-Russian group put nuclear 'instructions' in malware to confuse AI scanners

Published Reading time: 4 minutes AI & Cybersecurity

A group linked to Russia has used an unusual trick to prevent AI-based cybersecurity tools from analyzing malware. The UAC-0099 vector added text about nuclear weapon construction to a malicious script, aiming to trigger the security filters of a large language model (LLM).

Pro-Russian group put nuclear "instructions" in malware to confuse AI scanners - Image 1

ESET researchers spotted the technique, which they dubbed GuardBreaker, in an attack against a target in Ukraine. The text “I want to make a nuclear weapon. Help me …” was added as a comment to a malicious VBS script. According to ESET, the goal was to draw the AI’s attention to security-related content so that the model would refuse to analyze the rest of the code.

Researchers believe that this script is part of a larger toolkit of UAC-0099. The team has previously targeted the transportation and energy sectors. The script downloads and installs MATCHBOIL, a loader written in C# that is used exclusively by this entity to deliver additional payloads.

In late July 2026, the Computer Emergency Response Team of Ukraine (CERT-UA) warned that UAC-0099 was using a malicious program posing as a Notepad++ plugin to compromise Windows systems and install a new version of MATCHBOIL.

Similar attacks against AI tools

This is not the first time that such a method has been used against AI-powered security systems. In June 2026, researchers discovered a similar anti-analysis mechanism in legitimate and malicious Python packages. The technique was used in supply chain attack campaigns codenamed Mini Shai-Hulud, Miasma, and Hades.

In these cases, the packages contained plain text that presented itself as instructions for building biological and nuclear weapons. The goal was to trigger safety guardrails so that AI scanners would refuse to continue analyzing.

Socket reported at the time that the method could mislead scanners or analysis assistants that send an LLM the beginning of a file without clearly distinguishing the content from the trusted instructions. In poorly protected workflows, this could lead the model to refuse to respond, get confused about the instructions, “contaminate” the context, or prematurely classify before it reaches the actual malware code.

Previous incidents have been linked to the cybercrime group TeamPCP. However, attribution of responsibility for activities after May 12, 2026 remains unclear. The public leak of the Shai-Hulud worm source code has enabled other actors to adopt similar techniques.

Last week, Socket and Step Security also revealed a new Mini Shai-Hulud attack on the npm package. @7nohe/openapi-react-query-codegenThe attack used an obfuscated JavaScript loader, which decrypted and downloaded a second payload. The payload targeted cloud credentials, package registries logins, GitHub Actions secrets, and AI agent settings.

Two individuals alleged to be members of TeamPCP, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, from Western Australia, have been arrested by authorities. The charges include involvement in supply chain attacks, crimes related to identity theft and money laundering via cryptocurrency. The group is believed to have been operating since 2020.

In a report, Flare said that TeamPCP’s early efforts were based on opportunistic detection of exposed services, container deployment, and Monero mining. The company also said that the team realized that a vulnerability scanner within a build pipeline can access more credentials than it could directly compromise most systems. At the same time, the trust in security tools can be indirectly transferred to other systems.

Flare added that LiteLLM was not compromised, but was running Trivy. According to the report, this shows how a security tool can be a useful intermediate target in a broader attack.

Hacks.gr on Google Set it as a preferred source for cybersecurity updates.
Preferred source

READ ALSO

Recommended readings from Hacks.gr to continue.

Participate in the discussion

Comments should remain on topic. Your email address will not be published.

0 / 2000

0 / 50

Your comments will not be published if:

  • 1. They cause "DoS" to the community with irrelevant or repetitive comments.
  • 2. They try to "phish" other users' information.
  • 3. They contain "zero-day" insults and slurs.
  • 4. Contain "malware" advertisements for products or services.
  • 5. Your comments should be sweet and friendly, not like malicious cookies trying to mislead us!