GuardBreaker: Derailing AI-assisted malware analysis with a code comment

https://web-assets.esetstatic.com/wls/2026/09-26/guardbreaker-llm-guardrails-trip.png

Business Security

LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor

10 Sep 2026 • 4 min. read

Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way. Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection. Other tools – notably, EDR killers, documented extensively by ESET researchers – go straight after security solutions themselves.

As LLM-based tools increasingly assist with various security tasks, including code triage and analysis, it was only a matter of time before threat actors began to look for practical ways to subvert them, too. Alongside conventional evasion techniques, some are taking a different tack: the adversarial input that’s intended to frustrate analysis is left in plain sight.

ESET...

Copyright of this story solely belongs to www.welivesecurity.com. To see the full text click HERE

Read more