UAC-0099 Uses AI Guardrails Against Analysts

ESET says the Russia-aligned UAC-0099 group has started hiding a fake nuclear-weapon request inside a malicious VBS script to disrupt AI-assisted malware analysis. The script is part of the group's toolset for transportation and energy targets and still downloads and installs MATCHBOIL, the malware ESET ties to UAC-0099. The trick is simple: the scary comment is not code, but it is text an AI reviewer may react to first, so the model stops or narrows its analysis before it reaches the downloader and payload logic. That means the tooling layer can be steered away from the rest of the sample, even though the malware itself still runs as written. For teams that lean on AI to triage scripts and samples, the exposure is in the review workflow, not just the malware file. If AI output is treated as complete without manual follow-up, the missing context can be the downloader, the campaign link, or the rest of the chain.

Part of the PlainSec briefing for 2026-08-31

Editions

Sources