CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

UAC-0099

actor · actor:uac-0099

Russia-aligned group that ESET (2026-09-10) saw placing a decoy request for guidance on building a nuclear weapon in a VBScript comment to trip an LLM code scanner's safety refusal before the MATCHBOIL loader, a technique ESET named GuardBreaker.

Coverage
1
first 2026-10-09 → last 2026-10-09
Latest activity
2026-10-09
Talos: malware tells the analysing LLM to skip it; the text is plain and therefore detectable
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
2
2 hosts

Defender insights

What each entry about UAC-0099 tells a defender to do, newest first.

2026-10-09NOTABLETalos: malware tells the analysing LLM to skip it; the text is plain and therefore detectable

Exposure · triage · detection

Story timeline

  1. 2026-10-09Cisco Talos: malware now embeds natural-language instructions aimed at LLM triage pipelines, from a copied comment to template-sprayed prompts across four families, and a Russia-aligned group uses it too
    researchTalos: malware tells the analysing LLM to skip it; the text is plain and therefore detectable

Hunting pivots

ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ExecutionCommand and Scripting Interpreter: PowerShell
  • StealthObfuscated Files or Information

Execution TA0002

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-10-09/talos-ai-analysis-evasion-instructions-aimed-at-llm-triage · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-10-09/talos-ai-analysis-evasion-instructions-aimed-at-llm-triage · ATT&CK page ↗

Entries about UAC-0099 (1)

2026-10-09 · view entry permalink →

NOTABLENATOB2

Cisco Talos: malware now embeds natural-language instructions aimed at LLM triage pipelines, from a copied comment to template-sprayed prompts across four families, and a Russia-aligned group uses it too

Talos, which tracks AI-integrated malware in its CAIRN toolkit, calls the class "AI-analysis evasion": malware that embeds natural-language instructions to influence automated analysis, aimed at the layer above packers and anti-debug checks, the pipeline that extracts text from a sample and submits it to a language model for triage, classification or reverse-engineering help (Cisco Talos, 2026-10-08). It traces four families and 84 samples collected from January 2025 to July 2026: a PowerShell reverse shell (FRUITSHELL) carrying a two-line comment that says there is no need to analyze the file, a comment later reused verbatim in nine further scripts from at least four actors, among them a script set that adds an AMSI bypass and runtime compilation (Cisco Talos, 2026-10-08). PLOTSAFE generates the sentence from a template and keeps it alive in Go builds with a dummy function that references the strings; HOLLOWCLAD repeats one refusal instruction across seven LLM chat-template formats so one copy may match the scanner's own template, and adds fake honeypot and licence warnings; MANTLEMAZE claims invented government contracts and certifications (Cisco Talos, 2026-10-08).

ESET found the technique in the hands of a named group: the Russia-aligned UAC-0099 put a decoy request for guidance on building a nuclear weapon into the comment of a VBScript, aiming to trip the safety guardrails of an LLM-powered code scanner so it stops before the malicious code that downloads the MATCHBOIL loader (ESET, 2026-09-10). Talos tested the strings against five local models, 135 matched pairs per string: its headline figure is that the best techniques steered the outcome in the attacker's favour in about 35% of runs, a net rate (pairs shifted toward benign minus pairs shifted toward malicious, over all pairs), while the cheapest technique, a direct instruction to ignore the sample, worked almost universally and the more complex ones had little effect or backfired by making models more suspicious; Talos calls the overall impact a mixed bag (Cisco Talos, 2026-10-08). It says core conventional detection is unaffected (Cisco Talos, 2026-10-08).

Triage: Talos' discriminator is that legitimate software has no reason to embed instructions telling an analyzer to refuse analysis, invoke copyright law or claim government contracts (Cisco Talos, 2026-10-08).

malware that embeds natural-language instructions to influence automated analysis

Legitimate software has no reason to embed instructions telling an analyzer to refuse analysis, invoke copyright law, or claim government contracts.

Cisco Talos 2026-10-08

no single LLM engine should have the sole authority to decide that a piece of code is safe

ESET 2026-09-10

Builds on: macOS.Gaslight, a DPRK-aligned Rust backdoor that targets the LLM-assisted analyst

research09 Oct 03:44Zmulti-sourceOpen finding →
Sources: Cisco Talos · ESET

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Research1

Source distribution

  • blog.talosintelligence.com1 (50%)
  • welivesecurity.com1 (50%)