Actor Profile

UAC-0099 is a Russia-aligned threat actor with a documented history of targeting Ukraine's transportation and energy sectors. The group demonstrates tactical innovation by adapting emerging anti-analysis techniques, specifically targeting AI-assisted security workflows. UAC-0099 exclusively uses the MATCHBOIL C#-based loader as part of its custom toolset, indicating a preference for proprietary infrastructure. The actor's motivation aligns with Russian strategic interests in Ukraine, focusing on critical infrastructure disruption and intelligence collection.

TTPs (Tactics, Techniques, Procedures)

UAC-0099 employs the GuardBreaker technique, embedding adversarial prompt injections (nuclear weapon construction prompts) as comments in VBS scripts to trigger LLM safety mechanisms and prevent AI-assisted malware analysis. The group uses VBS scripts for initial payload delivery, downloading and installing MATCHBOIL, a custom C# loader for second-stage payload deployment. In July 2026, CERT-UA observed UAC-0099 masquerading malware as legitimate Notepad++ plugins to compromise Windows systems. The actor demonstrates awareness of modern security workflows and actively adapts tactics to evade AI-powered detection systems. Relevant MITRE ATT&CK techniques include T1059.005 (Command and Scripting Interpreter: Visual Basic), T1027 (Obfuscated Files or Information), T1036 (Masquerading), and T1204.002 (User Execution: Malicious File).

Targets & Patterns

UAC-0099 primarily targets Ukrainian organizations within the technology and defense sectors, with historical focus on transportation and energy infrastructure. The targeting pattern reflects strategic intelligence collection objectives aligned with Russian interests in Ukraine's critical infrastructure and defense capabilities. The actor's use of GuardBreaker against Ukrainian targets suggests awareness that these organizations may employ AI-assisted security analysis tools. The geographic focus remains concentrated on Ukraine, consistent with Russia-aligned threat actor operational priorities during ongoing geopolitical tensions. The selection of technology and defense sectors indicates intent to compromise sensitive systems and gather strategic intelligence.

Historical Context

UAC-0099's GuardBreaker technique represents an evolution of adversarial prompt injection tactics first observed in June 2026 during the Mini Shai-Hulud, Miasma, and Hades supply chain campaigns attributed to cybercrime group TeamPCP. Those campaigns embedded similar nuclear and biological weapon prompts in Python packages to bypass AI security scanners. Following the May 12, 2026 public leak of the Shai-Hulud worm source code, these anti-AI analysis techniques became available to multiple threat actors. UAC-0099's adoption of GuardBreaker demonstrates cross-pollination between cybercrime and nation-state tactics. The actor's consistent use of MATCHBOIL loader across campaigns provides continuity for tracking their operations. CERT-UA's July 2026 warning about Notepad++ plugin masquerading indicates ongoing UAC-0099 activity targeting Ukraine throughout 2026.

Defensive Recommendations

  • Implement content isolation in AI-assisted analysis pipelines to treat all analyzed code as untrusted data, preventing prompt injection attacks from affecting LLM behavior
  • Deploy multi-layered detection that does not rely solely on AI/LLM-based triage; combine static analysis, behavioral monitoring, and signature-based detection to ensure GuardBreaker-style evasion does not blind security operations
  • Monitor for VBS script execution (T1059.005) via Windows Script Host, particularly scripts downloading external payloads; enable PowerShell and VBS logging through Sysmon Event ID 1 and Windows Event ID 4688
  • Detect masquerading attempts (T1036) by validating digital signatures of plugins and extensions, especially for development tools like Notepad++; alert on unsigned or anomalous plugin installations
  • Hunt for MATCHBOIL C# loader indicators including network connections to known UAC-0099 infrastructure and file artifacts associated with the loader; correlate with CERT-UA published IOCs from July 2026 advisory

---

# Geopolitical Context

Geopolitical Context

The GuardBreaker technique represents an evolution in offensive cyber tradecraft consistent with Russia-aligned operations against Ukraine. UAC-0099's deployment of adversarial prompt injection—embedding nuclear weapon prompts to trigger LLM safety mechanisms—demonstrates adaptive targeting of emerging AI-assisted security workflows. This activity aligns with sustained Russian cyber operations against Ukrainian critical infrastructure, particularly in the technology and defense sectors. The technique's sophistication suggests state-aligned actors are actively studying and exploiting vulnerabilities in AI-powered security tools, which are increasingly deployed by Western and Ukrainian defenders. The timing—September 2026, amid ongoing conflict—indicates persistent Russian efforts to degrade Ukrainian cyber defense capabilities through technical innovation.

State Actor Alignment

UAC-0099 is assessed by ESET to be Russia-aligned, with a documented history of targeting Ukrainian transportation and energy sectors. While the actor's precise institutional affiliation remains unclear, the targeting pattern and operational tempo are consistent with Russian strategic interests in degrading Ukrainian critical infrastructure. The technique shares conceptual similarities with earlier adversarial prompt injection methods attributed to the cybercrime group TeamPCP (with two Australian nationals arrested in connection), though no direct operational link between UAC-0099 and TeamPCP has been established. The public leak of Shai-Hulud worm source code in May 2026 has complicated attribution, as multiple threat actors have since adopted similar anti-AI analysis tactics.

Business Impacty pro region

For Europe, GuardBreaker highlights emerging risks to AI-assisted cybersecurity infrastructure deployed across NATO and EU member states. Ukrainian targets in technology and defense sectors face continued pressure from adaptive Russian cyber operations. The technique's disclosure may accelerate European investment in adversarial-resistant AI security tools and prompt regulatory scrutiny of LLM safety mechanisms in critical infrastructure protection. Globally, the incident underscores the dual-use nature of AI safety features: guardrails designed to prevent harmful outputs can be weaponized to blind security systems. Organizations relying on LLM-based malware triage—particularly in supply chain security—face heightened risk if prompt isolation and content sanitization are inadequate.

Forecast

If adversarial prompt injection techniques continue to proliferate following the Shai-Hulud source code leak, defenders are likely to prioritize sandboxing untrusted content before LLM analysis and implementing multi-layered triage systems that do not rely solely on AI. If UAC-0099 maintains operational tempo against Ukrainian infrastructure, additional GuardBreaker variants targeting other AI security tools may emerge in the coming months. Should Western security vendors fail to harden LLM-based analysis pipelines, state-aligned actors are likely to expand use of safety-mechanism exploitation beyond Ukraine, particularly against high-value targets in NATO member states. Conversely, if AI security tooling rapidly adapts—through better prompt isolation and hybrid human-AI workflows—the operational lifespan of GuardBreaker-style techniques may be limited to early adopters with immature AI integration.