Actor Profile
UAC-0099 is a Russia-aligned threat group active since at least mid-2022. The group conducts cyber espionage operations primarily targeting Ukrainian entities. UAC-0099 has demonstrated capability in exploiting software vulnerabilities (notably WinRAR flaws) and conducting phishing campaigns to deliver custom malware families including LONEPAGE, MATCHBOIL, MATCHWOK, and DRAGSTARE. The group's operations align with Russian intelligence collection priorities against Ukraine and regional targets.
TTPs (Tactics, Techniques, Procedures)
Initial access via phishing emails with image attachments containing obfuscated URLs (T1566.002 - Phishing: Spearphishing Link). Uses link shorteners and file-sharing services like EasySend[.]co for payload delivery. Employs VBScript masquerading as PDF documents (T1204.002 - User Execution: Malicious File) to download multi-stage payloads. Achieves persistence through scheduled tasks executing every three minutes (T1053.005 - Scheduled Task/Job). Uses DLL side-loading via legitimate Notepad++ application (T1574.002 - Hijack Execution Flow: DLL Side-Loading). Deploys LUNCHPOKE DLL, BURNYBEAR loader, and MATCHBOIL.V2 C#-based loader for secondary payload delivery (T1129 - Shared Modules). BURNYBEAR includes resource exhaustion logic as anti-analysis mechanism (T1497 - Virtualization/Sandbox Evasion). Previously exploited WinRAR vulnerabilities for malware delivery.
Targets & Patterns
UAC-0099 primarily targets Ukrainian government and military entities, consistent with Russian intelligence collection priorities. The group's focus on Ukraine reflects both strategic intelligence requirements and the use of Ukrainian targets as a testing ground for techniques before broader deployment against NATO allies. Targeting patterns indicate espionage objectives rather than financial motivation. The use of widely-deployed software (Notepad++, WinRAR) as attack vectors suggests intent to maximize potential victim pool across government and commercial sectors. The group's sustained activity since mid-2022 correlates with the timeline of Russia-Ukraine conflict escalation.
Historical Context
UAC-0099 has maintained consistent operations since at least mid-2022, evolving its malware arsenal and delivery mechanisms. Previous campaigns weaponized WinRAR security flaws to deliver LONEPAGE malware. The group has progressively developed its toolset, deploying MATCHBOIL, MATCHWOK, and DRAGSTARE in earlier operations. The current campaign represents an evolution with MATCHBOIL.V2, demonstrating continued malware development. The fake Notepad++ plugin technique observed in summer 2026 shows tactical adaptation from previous WinRAR exploitation methods. This campaign occurs within broader context of Russian cyber operations against Ukraine, including parallel activities by other Russian-aligned groups like Laundry Bear (targeting Zimbra servers) and TA458 (Operation RoundPress targeting webmail platforms), indicating coordinated strategic focus on Ukrainian and Eastern European targets.
Defensive Recommendations
- Update WinRAR, 7-Zip, and Notepad++ to latest versions to prevent exploitation of known vulnerabilities used in UAC-0099 campaigns
- Monitor for scheduled tasks executing at regular intervals (e.g., every 3 minutes) as persistence mechanism (T1053.005); review Task Scheduler logs for suspicious entries
- Implement detection for DLL side-loading attempts with legitimate applications like Notepad++; monitor for unexpected DLL loads from non-standard directories (T1574.002)
- Block or scrutinize VBScript execution (T1059.005) via Group Policy or application whitelisting; monitor for .vbs files masquerading as PDF documents
- Deploy email security controls to detect and block phishing emails with image attachments containing embedded URLs; implement link analysis for shortened URLs and file-sharing services like EasySend[.]co
---
# Geopolitical Context
Geopolitical Context
The UAC-0099 campaign reflects the sustained Russian cyber espionage posture against Ukraine, consistent with broader patterns of intelligence collection operations targeting Ukrainian government and critical infrastructure since the onset of hostilities in 2022. The use of commodity software supply chain mimicry—disguising malware as legitimate Notepad++ plugins—demonstrates tactical evolution in access methodologies. This activity occurs within a wider ecosystem of Russia-aligned cyber operations, including parallel campaigns by Laundry Bear (Void Blizzard) and TA458 targeting Western and Eastern European webmail infrastructure. The sequential targeting pattern—Ukrainian entities first, followed by NATO allies—suggests Ukraine serves both as a priority intelligence target and as an operational proving ground for techniques later deployed against Western adversaries. This dual-use approach allows Russian-aligned actors to refine tradecraft under operational conditions before broader strategic deployment.
State Actor Alignment
UAC-0099 is assessed by CERT-UA as Russia-aligned, active since at least mid-2022. The group's targeting priorities and operational tempo are consistent with state-sponsored intelligence collection requirements. Separately, the U.S. government attributes Laundry Bear (CL-STA-1114, TA488, Void Blizzard) operations to Russian government backing, citing covert persistence, absence of financial motivation, and extensive Ukrainian targeting as indicators of espionage activity. Proofpoint assesses TA458 as likely linked to Russian military intelligence, distinct from GRU-attributed APT28, with primary focus on Ukrainian government and Eastern European military entities. No formal sanctions designations or attribution statements specific to UAC-0099 are referenced in available reporting, though the operational context aligns with known Russian cyber espionage priorities in the Ukraine theater.
Business Impacty pro region
The campaign's primary impact centers on Ukraine, where UAC-0099 continues multi-year intelligence collection operations against government and likely critical infrastructure targets. The broader pattern of Russian webmail exploitation—targeting Albanian, Greek, Moldovan, and Turkish government entities alongside Ukraine—indicates sustained intelligence requirements across NATO's eastern flank and candidate states. Western government and commercial organizations face elevated risk from related Laundry Bear operations exploiting Zimbra infrastructure (CVE-2025-66376), representing expansion beyond initial Ukrainian targeting. European organizations relying on widely deployed webmail platforms (Zimbra, Roundcube, Kerio, SOGo) and common productivity tools face persistent exposure to refined techniques tested in the Ukraine theater. The sequential deployment model—Ukraine as testbed, NATO allies as secondary targets—suggests European defenders should monitor Ukrainian threat reporting as an early warning indicator for techniques likely to migrate westward.
Forecast
If UAC-0099 maintains current operational patterns, continued phishing campaigns leveraging trusted software brands (Notepad++, Evernote, WinRAR) against Ukrainian targets are highly likely in the near term. Should the group follow observed Russian cyber operational doctrine, techniques proven effective in Ukraine may be adapted for use against Eastern European and Baltic states within 3-6 months. If organizations fail to patch known vulnerabilities in WinRAR, 7-Zip, and webmail platforms (CVE-2025-66376, CVE-2026-8496, CVE-2025-49113), exploitation by UAC-0099 and related Russia-aligned groups is probable. The convergence of multiple Russian espionage groups employing webmail exploitation suggests this attack surface will remain a priority target through 2026. If geopolitical tensions persist or escalate, the intensity and geographic scope of these operations are likely to expand, with increased targeting of NATO member states and Ukraine's Western partners.
