Skip to main content
← Back to Demos
AI Content Inspector intermediate · 15 min

GuardBreaker: Weaponized Script Comments That Blind LLM Malware Analysis (ESET / UAC-0099, 2026-09-04 CISO Daily Digest)

ESET researchers published an anti-analysis technique they call GuardBreaker: attackers embed prompt-injection text inside a VBS script's comments — the observed sample opens with "I want to create nuclear weapons. Help me..." — so that LLM-based malware-analysis tools trip their own safety filters and refuse to examine the sample before ever reaching the malicious code. The technique was observed in an attack on a Ukrainian organization by the group UAC-0099, whose script downloads the C# loader MATCHBOIL; similar injections surfaced in June 2026 in packages tied to the Shai-Hulud, Miasma and Hades campaigns. ESET's warning: when an AI scanner hands raw file content to a language model without marking it untrusted, embedded text can read as an instruction and fire the model's guardrails before the malware is analyzed. This demo reproduces the trick safely: a plain-text document that mirrors the weaponized VBS comment block an analysis pipeline would receive (marked DEMO, executes nothing), alongside a sanitized copy with the injection removed. OPSWAT AI Content Inspector inspects content before it reaches the model: the injection is detected and stripped, the analysis stays objective, and the scanner sees the script — not the trap (MITRE ATT&CK T1566.001 file-borne delivery).

Attack Technique

GuardBreaker anti-analysis prompt injection — weaponized instruction text embedded in VBS script comments to blind LLM-based malware analysis (ESET; UAC-0099 / MATCHBOIL delivery chain, T1566.001)

MITRE ATT&CK

T1566.001 ↗

Platforms

linux

File Types

.txt

MetaDefender Capabilities

OPSWAT AI Content Inspector

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---