UAC-0099 Tries to Fool LLM Malware Triage

ESET found UAC-0099 using a VBScript decoy comment in an early-stage intrusion against a target in Ukraine, with the group inserting a fake request for help building a nuclear weapon to derail LLM-based code scanning. The script’s actual job was to download and install MATCHBOIL, a loader ESET says this group uses to deliver more payloads. The comment does nothing at runtime; it is there to make the analyzer stop early on safety grounds before it reaches the malicious code. That turns the inspection pipeline itself into the target, because a model that refuses on the bait can produce a false negative and leave the loader unreviewed. The broader shift is that attackers are now shaping visible file content for the tools and people inspecting it, not just hiding behavior from execution-time defenses. If your first-pass triage trusts an LLM’s refusal or summary, that trust can now be steered by the sample itself.

Part of the PlainSec briefing for 2026-09-11

Every edition of this story: UAC-0099 Tries to Fool LLM Malware Triage

Sources