UAC-0099 is a Russia-aligned cyber-espionage threat cluster active since at least mid-2022 and primarily focused on Ukrainian targets. The group has repeatedly targeted Ukrainian state authorities, defense forces, and defense-industrial enterprises, and has also been associated with operations against Ukrainian organizations more broadly. Reporting has linked the cluster to providing initial access for follow-on activity by Sandworm/APT44, indicating a role as an access and espionage operator within the broader Russian threat ecosystem. UAC-0099 is best known for phishing-led intrusions that deliver staged malware chains using archive files, HTA or VBScript launchers, obfuscated PowerShell, scheduled-task persistence, and abuse of legitimate software. The group has used phishing emails themed as official correspondence such as court summons or administrative documents, often directing victims to legitimate file-hosting services. In later activity, the actor shifted to delivering trojanized application bundles that abuse normal plugin-loading behavior in legitimate software, including Notepad++, to sideload malicious DLLs. This tooling included LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2, with persistence established through scheduled tasks and follow-on payload retrieval. Earlier and parallel campaigns used MATCHBOIL as a loader, MATCHWOK as a backdoor, DRAGSTARE as an infostealer, and LONEPAGE in campaigns involving WinRAR exploitation. The cluster demonstrates strong initial-access and post-compromise tradecraft centered on spearphishing, DLL sideloading, loader deployment, persistence, and payload staging. Observed capabilities include host fingerprinting, remote payload download and execution, command execution via PowerShell, configuration updates, credential and browser-data theft, document collection, and data exfiltration. Anti-analysis and defense-evasion behaviors have also been documented, including sandbox-frustration and checks for analysis tools. UAC-0099 is assessed as an espionage-focused actor rather than a ransomware or financially motivated group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
62 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a phishing-led malware campaign that abuses a legitimate Notepad++ installation to sideload a malicious DLL, leading to deployment of LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2, persistence via scheduled tasks, and follow-on payload delivery.
Conducting phishing-led intrusions against Ukrainian organizations using a trojanized Notepad++ plugin to deploy a staged malware chain including LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2; previously associated with exploiting WinRAR vulnerabilities and delivering LONEPAGE, MATCHBOIL, and DRAGSTARE.
Russia-aligned threat cluster conducting phishing-led intrusions against Windows systems, including a campaign using a fake Notepad++ plugin chain to deploy LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2; previously used WinRAR flaws to deliver LONEPAGE and has also deployed MATCHBOIL, MATCHWOK, and DRAGSTARE.
Conducting a malware delivery and persistence campaign using a trojanized Notepad++ plugin mechanism to target Ukrainian organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.