B
今週中
ロシア系脅威アクターUAC-0099が、AIによる解析を妨害する「GuardBreaker」という新手法を用いたこと
📌 一言でいうと
ロシア系脅威アクターUAC-0099が、AIによる解析を妨害する「GuardBreaker」という新手法を用いたことが判明しました。攻撃者は悪意のあるVBSスクリプト内に「核兵器を作りたい」という安全フィルターに抵触する文言をコメントとして挿入し、LLMの安全メカニズムを意図的に作動させて解析を停止させようとします。このスクリプトは、主にMATCHBOILというC#ベースのローダーをインストールするために使用されます。
🔍該当判定
- ChatGPTやClaudeなどのAIツールに、不審なVBSファイル(.vbs)の中身を貼り付けて解析させている
- 社内でVBScript(.vbsファイル)を利用した業務自動化やツールを運用している
- エネルギー業界や輸送・物流業界に従事しており、ロシア関連の攻撃グループの標的になる可能性がある
上記いずれにも該当しない → 静観でOK
✅該当時の対応
AIによるコード解析に依存せず、従来の静的・動的解析手法を併用すること。また、不審なVBSスクリプトの実行を制限するエンドポイントセキュリティ対策を強化してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】UAC-0099によるAI解析妨害手法(GuardBreaker)について
お疲れさまです。ロシア系アクターUAC-0099による新しい解析妨害手法に関する情報共有です。
■ 概要
攻撃者がVBSスクリプト内にLLMの安全フィルターを意図的に作動させるプロンプト(例:「核兵器を作りたい」等)を挿入し、AIによるマルウェア解析を停止させる「GuardBreaker」手法が確認されました。これにより、AIを用いた自動解析ツールが正常に動作しなくなる可能性があります。
■ 影響範囲
- AIベースのコード解析ツールを利用してマルウェア分析を行っているセキュリティチーム
- UAC-0099の標的となる輸送・エネルギーセクター
■ 対応手順
1. AI解析ツールのみに依存せず、従来のサンドボックス解析やリバースエンジニアリングを併用する体制を維持してください。
2. VBSスクリプト等の実行を制限するポリシーの再確認および適用を行ってください。
■ 参考情報
- ESET Security Report
対応優先度: 低
対応期限: なし
お疲れさまです。ロシア系アクターUAC-0099による新しい解析妨害手法に関する情報共有です。
■ 概要
攻撃者がVBSスクリプト内にLLMの安全フィルターを意図的に作動させるプロンプト(例:「核兵器を作りたい」等)を挿入し、AIによるマルウェア解析を停止させる「GuardBreaker」手法が確認されました。これにより、AIを用いた自動解析ツールが正常に動作しなくなる可能性があります。
■ 影響範囲
- AIベースのコード解析ツールを利用してマルウェア分析を行っているセキュリティチーム
- UAC-0099の標的となる輸送・エネルギーセクター
■ 対応手順
1. AI解析ツールのみに依存せず、従来のサンドボックス解析やリバースエンジニアリングを併用する体制を維持してください。
2. VBSスクリプト等の実行を制限するポリシーの再確認および適用を行ってください。
■ 参考情報
- ESET Security Report
対応優先度: 低
対応期限: なし
Subject: [Intel] AI Analysis Disruption Technique (GuardBreaker) by UAC-0099
Dear Team,
We are sharing information regarding a new technique called 'GuardBreaker' used by the Russia-aligned actor UAC-0099.
■ Overview
UAC-0099 has been observed inserting safety-sensitive strings (e.g., prompts about creating nuclear weapons) into VBS script comments. This is designed to trigger the safety mechanisms of Large Language Models (LLMs), effectively stopping AI-assisted tools from analyzing the malicious code.
■ Scope
- Security teams relying on AI-based code analysis for malware triage.
- Transportation and energy sectors (primary targets of UAC-0099).
■ Recommended Actions
1. Ensure that malware analysis workflows include traditional static and dynamic analysis to complement AI tools.
2. Review and enforce policies restricting the execution of unauthorized VBS scripts.
■ Reference
- ESET Security Report
Priority: Low
Deadline: N/A
Dear Team,
We are sharing information regarding a new technique called 'GuardBreaker' used by the Russia-aligned actor UAC-0099.
■ Overview
UAC-0099 has been observed inserting safety-sensitive strings (e.g., prompts about creating nuclear weapons) into VBS script comments. This is designed to trigger the safety mechanisms of Large Language Models (LLMs), effectively stopping AI-assisted tools from analyzing the malicious code.
■ Scope
- Security teams relying on AI-based code analysis for malware triage.
- Transportation and energy sectors (primary targets of UAC-0099).
■ Recommended Actions
1. Ensure that malware analysis workflows include traditional static and dynamic analysis to complement AI tools.
2. Review and enforce policies restricting the execution of unauthorized VBS scripts.
■ Reference
- ESET Security Report
Priority: Low
Deadline: N/A