Have you heard about the latest technique that attackers are using to bypass security defenses?
10 Sep 2026
•
,
4 min. read
It seems that malware developers are always one step ahead when it comes to evading detection. They have now found a way to outsmart LLM-based code scanners by incorporating decoy requests within their code. In a recent attack by the Russia-aligned group UAC-0099, a VBScript contained a fake request for guidance on building a nuclear weapon, designed to trigger the safety guardrails of an LLM-powered scanner and divert attention away from the actual malicious code.
This clever technique, dubbed GuardBreaker by ESET researchers, highlights the ongoing battle between attackers and security tools. By leveraging the refusal of LLM models to engage with certain types of content, threat actors are finding new ways to slip past defenses.
But GuardBreaker is just the tip of the iceberg. Similar anti-analysis tactics have been observed in various cyber attacks, with attackers deploying different methods to confuse and disrupt LLM-powered scanners. From prompt injections to fabricated system instructions, the arsenal of evasion techniques is constantly evolving.
Stay vigilant against evolving threats
It’s clear that attackers will stop at nothing to achieve their goals. As businesses increasingly rely on LLM-powered technologies for security tasks, it’s essential to understand the limitations and vulnerabilities of these tools. A multi-layered approach that combines automation with human expertise is crucial to outsmarting sophisticated attacks like GuardBreaker.
Remember, no single technology can provide foolproof protection against determined adversaries. By staying informed about the latest threats and continuously enhancing your security posture, you can stay one step ahead of cybercriminals.
For more insights on AI-powered security solutions, visit ESET’s AI page.


