BURNYBEAR: Loader Used in UAC-0099 Attacks
BURNYBEAR is a loader used by UAC-0099 to deliver MATCHBOIL.V2. It is executed as RemoteLibUpdater.exe and can exhaust system resources if launched…
BURNYBEAR is a loader used by UAC-0099 to deliver MATCHBOIL.V2. It is executed as RemoteLibUpdater.exe and can exhaust system resources if launched…
LUNCHPOKE is a malicious DLL (NppExport.dll) that unpacks a RAR archive containing BURNYBEAR and MATCHBOIL.V2. It sets up persistence via a scheduled…
Notepad++ is a free source code editor that was abused in UAC-0099 attacks by bundling a malicious plugin (NppExport.dll) to deliver malware.
EasySend.co is a file-sharing service used by UAC-0099 to host malicious ZIP archives in their phishing campaign.
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
UAC-0099 is a Russia-aligned threat cluster tracked by CERT-UA, active since at least mid-2022. It has used phishing emails and exploits in…
MATCHBOIL.V2 is a modified version of the MATCHBOIL malware, a C#-based loader capable of delivering secondary payloads. It was deployed in attacks…
WinRAR is a file archiver utility that has been exploited by UAC-0099 in previous attacks and used legitimately in the latest campaign…