BURNYBEAR is a Windows malware loader associated with the Russia-aligned UAC-0099 threat cluster and observed in phishing campaigns targeting Ukrainian organizations. It appears in a multi-stage intrusion chain that abuses a trojanized Notepad++ plugin to deploy follow-on malware. After initial delivery via phishing and execution of a disguised VBScript, a malicious plugin component extracts BURNYBEAR and configures scheduled-task persistence so it is launched repeatedly with specific command-line arguments. BURNYBEAR’s primary role is to load a secondary DLL payload identified as MATCHBOIL.V2, an updated variant of the MATCHBOIL loader used to retrieve and execute additional malicious components and update configuration data. When executed without its expected arguments, BURNYBEAR activates a resource-exhaustion routine that deliberately consumes significant CPU and memory, likely as a sabotage or anti-analysis measure. The malware is part of a broader staged toolset that relies on legitimate utilities for unpacking and blends into normal application behavior through DLL sideloading and scheduled-task execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The executable, identified as BURNYBEAR, deploys a payload named “InitTest.dll” on the system. It has also been determined that, when launched without the expected command-line arguments, the malware attempts to consume substantial memory and CPU resources on the compromised device.
These files include components like BurnyBear, a loader for the MatchBoil V2 malware, and RemoteLibUpdater.exe, which updates command-and-control addresses and uses WinRAR to extract downloaded payloads.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
LUNCHPOKE, the DLL is designed to unpack the RAR archive... to a specific directory, set up persistence by means of a scheduled task to run "RemoteLibUpdater.exe" every three minutes.
A scheduled task named \W1n3r-U09oTy-Ap5\Updates is subsequently created on the system. To maintain persistence, the task launches “RemoteLibUpdater.exe” with the setup nodisplay arguments every three minutes.
У згаданому архіві міститься VBS-скрипт... у разі запуску скрипт забезпечить завантаження файлу-приманки...
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An executable payload (RemoteLibUpdater.exe) deployed by LUNCHPOKE that is run persistently via scheduled task. It deploys InitTest.dll and, when executed without expected arguments, attempts to consume significant CPU and memory resources on the infected host.
A loader used by UAC-0099 to execute InitTest.dll; if launched without the expected arguments, it deliberately consumes RAM and CPU, likely to hinder analysis and disrupt sandbox execution.
A loader deployed by LUNCHPOKE that executes InitTest.dll, a modified MATCHBOIL variant, and includes fallback logic to exhaust system RAM and CPU if launched without arguments.
A loader component delivered in the campaign that is used to load MatchBoil V2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.