UAC-0099
actor · actor:uac-0099
Russia-aligned group that ESET (2026-09-10) saw placing a decoy request for guidance on building a nuclear weapon in a VBScript comment to trip an LLM code scanner's safety refusal before the MATCHBOIL loader, a technique ESET named GuardBreaker.
Defender insights
What each entry about UAC-0099 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionCommand and Scripting Interpreter: PowerShell
- StealthObfuscated Files or Information
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-10-09/talos-ai-analysis-evasion-instructions-aimed-at-llm-triage · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-10-09/talos-ai-analysis-evasion-instructions-aimed-at-llm-triage · ATT&CK page ↗
Entries about UAC-0099 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- blog.talosintelligence.com1 (50%)
- welivesecurity.com1 (50%)