UAC-0099 is a Russia-aligned cyber threat cluster active since at least mid-2022 and primarily focused on operations against Ukrainian organizations. The group has been associated with espionage-oriented intrusions and is assessed to play an initial-access role in some broader Russian operations, including handoffs to Sandworm/APT44 for follow-on activity. Reporting has linked the cluster to sustained targeting of Ukrainian government bodies, defense forces, and enterprises in the defense-industrial base. UAC-0099 is known for phishing-led intrusion chains that use social engineering themes relevant to Ukrainian recipients. Observed delivery methods include archives reached through phishing links, malicious shortcut files, VBScript disguised as documents through double extensions, and other loader-based mechanisms. The cluster has also been tied to exploitation of WinRAR vulnerabilities in earlier activity. Its malware ecosystem includes LONEPAGE, MATCHBOIL, MATCHBOIL.V2, MATCHWOK, DRAGSTARE, LUNCHPOKE, and BURNYBEAR. A notable 2026 campaign abused a legitimate copy of Notepad++ by placing a malicious plugin DLL in the application’s plugin directory so that it would be loaded through normal program behavior. In that chain, the LUNCHPOKE component unpacked additional malware, established persistence with scheduled tasks, and launched BURNYBEAR, which in turn loaded MATCHBOIL.V2. MATCHBOIL.V2 was reported as capable of updating configuration, downloading additional payloads, and maintaining persistence. BURNYBEAR also included resource-exhaustion behavior when executed without expected arguments, likely as an anti-analysis or disruptive measure. The cluster’s tradecraft demonstrates strong emphasis on initial compromise, persistence, payload staging, and follow-on malware delivery. High-confidence behaviors include phishing-based initial access, DLL sideloading or plugin abuse, scheduled-task persistence, downloading and executing additional payloads, and data theft through infostealer tooling such as DRAGSTARE. UAC-0099 has been described as Russia-aligned and linked in multiple reports to operations supporting Russian objectives in the war against Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
66 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a phishing-led malware campaign that abuses a legitimate Notepad++ installation to sideload a malicious DLL, leading to deployment of LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2, persistence via scheduled tasks, and follow-on payload delivery.
Conducting phishing-led intrusions against Ukrainian organizations using a trojanized Notepad++ plugin to deploy a staged malware chain including LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2; previously associated with exploiting WinRAR vulnerabilities and delivering LONEPAGE, MATCHBOIL, and DRAGSTARE.
Russia-aligned threat cluster conducting phishing-led intrusions against Windows systems, including a campaign using a fake Notepad++ plugin chain to deploy LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2; previously used WinRAR flaws to deliver LONEPAGE and has also deployed MATCHBOIL, MATCHWOK, and DRAGSTARE.
Conducting a malware delivery and persistence campaign using a trojanized Notepad++ plugin mechanism to target Ukrainian organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.