UAC-0099 is a Russia-aligned threat cluster tracked by CERT-UA, active since at least mid-2022. It has used phishing emails and exploits in WinRAR to deliver malware such as LONEPAGE, MATCHBOIL, MATCHWOK, and DRAGSTARE. The group recently deployed a fake Notepad++ plugin to deliver MATCHBOIL.V2.