BURNYBEAR is a Windows loader used in phishing-driven intrusion chains attributed to the Russia-aligned UAC-0099 threat cluster, including campaigns targeting Ukrainian organizations. It is deployed by the LUNCHPOKE malicious Notepad++ plugin and is configured for scheduled execution to provide persistence. BURNYBEAR loads the MATCHBOIL.V2 DLL loader, enabling follow-on payload delivery. When executed without its expected command-line arguments, BURNYBEAR deliberately consumes substantial CPU and memory resources, a behavior likely intended to impede analysis or disrupt the compromised host.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The executable, identified as BURNYBEAR, deploys a payload named “InitTest.dll” on the system. It has also been determined that, when launched without the expected command-line arguments, the malware attempts to consume substantial memory and CPU resources on the compromised device.
These files include components like BurnyBear, a loader for the MatchBoil V2 malware, and RemoteLibUpdater.exe, which updates command-and-control addresses and uses WinRAR to extract downloaded payloads.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
LUNCHPOKE, the DLL is designed to unpack the RAR archive... to a specific directory, set up persistence by means of a scheduled task to run "RemoteLibUpdater.exe" every three minutes.
A scheduled task named \W1n3r-U09oTy-Ap5\Updates is subsequently created on the system. To maintain persistence, the task launches “RemoteLibUpdater.exe” with the setup nodisplay arguments every three minutes.
У згаданому архіві міститься VBS-скрипт... у разі запуску скрипт забезпечить завантаження файлу-приманки...
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a component of the CERT-UA-documented infection chain; no capabilities are described in this content.
An executable payload (RemoteLibUpdater.exe) deployed by LUNCHPOKE that is run persistently via scheduled task. It deploys InitTest.dll and, when executed without expected arguments, attempts to consume significant CPU and memory resources on the infected host.
A loader used by UAC-0099 to execute InitTest.dll; if launched without the expected arguments, it deliberately consumes RAM and CPU, likely to hinder analysis and disrupt sandbox execution.
A loader deployed by LUNCHPOKE that executes InitTest.dll, a modified MATCHBOIL variant, and includes fallback logic to exhaust system RAM and CPU if launched without arguments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.