BURNYBEAR is a .NET-based Windows loader used by the Russia-aligned threat actor UAC-0099, also tracked as Earth Sirrush, in campaigns targeting Ukrainian organizations. Documented in an infection chain observed in mid-summer 2026, its primary function is to load MATCHBOIL.V2, a modified C# loader responsible for downloading and executing additional malware. If launched without the expected command-line arguments, BURNYBEAR activates resource-exhaustion logic that consumes substantial RAM and CPU resources.
The delivery chain begins with phishing emails containing images linked to file-sharing services through shortened URLs. Victims download archives containing VBScript files disguised as PDF documents through deceptive double extensions and spacing. Executing the script displays a decoy document and retrieves a package containing legitimate Notepad++ software and the malicious LUNCHPOKE plugin. Notepad++ loads LUNCHPOKE through its normal plugin mechanism, without requiring exploitation of a Notepad++ vulnerability. LUNCHPOKE extracts BURNYBEAR and MATCHBOIL.V2 from a password-protected archive and creates a scheduled task that repeatedly launches BURNYBEAR with the required arguments. Configuration updates, further payload retrieval, and archive extraction are functions of MATCHBOIL.V2 rather than BURNYBEAR itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAC-0099 : nouveaux outils LUNCHPOKE, BURNYBEAR et MATCHBOIL.V2 via DLL hijacking Notepad++
LUNCHPOKE deploys BURNYBEAR, a .NET loader, and MATCHBOIL.V2, an updated loader with stronger encryption and revised concealment.
These files include components like BurnyBear, a loader for the MatchBoil V2 malware, and RemoteLibUpdater.exe, which updates command-and-control addresses and uses WinRAR to extract downloaded payloads.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
LUNCHPOKE, the DLL is designed to unpack the RAR archive... to a specific directory, set up persistence by means of a scheduled task to run "RemoteLibUpdater.exe" every three minutes.
A scheduled task named \W1n3r-U09oTy-Ap5\Updates is subsequently created on the system. To maintain persistence, the task launches “RemoteLibUpdater.exe” with the setup nodisplay arguments every three minutes.
У згаданому архіві міститься VBS-скрипт... у разі запуску скрипт забезпечить завантаження файлу-приманки...
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET loader listed among UAC-0099's tools used during April–July 2026.
A .NET loader deployed by the malicious LUNCHPOKE plugin in Earth Sirrush's Ukrainian espionage operations. Its individual loading behavior is not detailed.
.NET loader deployed by the malicious LUNCHPOKE plugin in Earth Sirrush's attacks against Ukrainian organizations. The content does not detail its individual loading mechanism.
Named malware mentioned in the discussion of UAC-0099's infection chain. The content does not establish its specific functionality or whether it contains the AI-disruption prompt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.