BURNYBEAR is a Windows malware loader associated with the UAC-0099 threat cluster and observed in campaigns targeting organizations in Ukraine. It appears in a multi-stage intrusion chain that abuses the normal plugin-loading behavior of a bundled Notepad++ installation to execute a malicious plugin, which then extracts and launches BURNYBEAR alongside an additional DLL payload.
Its primary role is to load a secondary DLL identified as MATCHBOIL.V2. In the observed chain, an earlier component establishes persistence via scheduled tasks and repeatedly launches BURNYBEAR with specific arguments so that the loader can execute the next-stage implant. When started without its expected arguments, BURNYBEAR has also been observed activating a fallback routine that deliberately exhausts host CPU and memory resources, indicating a built-in disruptive capability in addition to its loader function.
BURNYBEAR has been delivered through phishing-based infection chains involving archives and a disguised script that retrieves a trojanized software package. The package contains a legitimate Notepad++ executable together with a malicious plugin used for DLL sideloading, after which BURNYBEAR is unpacked and executed. The broader malware chain supports persistence, configuration updates, command-and-control changes, and delivery of additional payloads through the downstream MATCHBOIL.V2 component.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RemoteLibUpdater.exe is classified as BURNYBEAR, whose job is loading InitTest.dll. Interestingly, if BURNYBEAR runs without its expected arguments, it switches to a resource-exhaustion routine that deliberately hogs RAM and CPU.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
It registers a scheduled task under a randomized name to relaunch RemoteLibUpdater.exe every three minutes with the arguments 'setup nodisplay.'
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader that executes InitTest.dll (MATCHBOIL.V2). If launched without expected arguments, it triggers a RAM/CPU exhaustion routine, likely as anti-analysis or decoy behavior.
A loader delivered from the extracted archive that launches the MatchBoil V2 DLL loader and includes a fallback resource-exhaustion mechanism if execution fails.
Executable loader used to load InitTest.dll. If executed without the expected arguments, it instead triggers resource-exhaustion behavior affecting CPU and memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.