Ukrainian Threat Actor UAC-0099 Continues Targeted Attacks: An In-Depth Analysis

The threat actor known as UAC-0099 has been linked to a series of persistent attacks directed at Ukraine, with a particular focus on Ukrainian employees working for companies outside of the country. This article provides an in-depth analysis of the tactics employed by UAC-0099, including the exploitation of a high-severity flaw in the widely used WinRAR software.

Background of UAC-0099

UAC-0099 first came to the attention of the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2023. The team documented the threat actor’s attacks against state organizations and media entities, with the primary motive believed to be espionage. These attacks marked the onset of UAC-0099’s activities and the subsequent evolution of their techniques.

Attack Techniques Used by UAC-0099

UAC-0099 has employed a variety of attack techniques to infiltrate target systems. One prominent method involves the use of phishing messages containing various file attachments, including HTA, RAR, and LNK files. These attachments, upon interaction, deploy a malware strain called LONEPAGE, which is used by UAC-0099 to gain control over compromised systems. A noteworthy aspect of this technique is the exploitation of a high-severity vulnerability (CVE-2023-38831) present in WinRAR, allowing for the distribution of LONEPAGE through ZIP files.

Detailed Analysis of Attack Techniques

UAC-0099 employs a clever disguise by using an SFX file that houses an LNK shortcut. This shortcut poses as a DOCX file related to a court summons, utilizing the icon for Microsoft WordPad in an attempt to entice the victim into opening it. Once accessed, malicious PowerShell code is executed, leading to the installation of the LONEPAGE malware.

Another attack method utilized by UAC-0099 involves the creation of a specially crafted ZIP archive susceptible to the aforementioned WinRAR vulnerability (CVE-2023-38831). When targeted individuals interact with these ZIP archives, the vulnerability is exploited, resulting in the installation of the LONEPAGE malware.

Analysis of UAC-0099’s Tactics

The tactics employed by UAC-0099 are characterized by their simplicity and effectiveness. By leveraging well-known vulnerabilities, disguising malicious files, and utilizing social engineering techniques through phishing messages, UAC-0099 is successful in infiltrating target systems. Despite the various initial infection vectors, the core infection remains consistent, relying on PowerShell and the creation of a scheduled task that executes a VBScript (VBS) file.

Warning from CERT-UA Regarding New Phishing Campaign

CERT-UA has recently issued a warning regarding a new wave of phishing messages claiming outstanding Kyivstar dues. These messages serve as a vehicle for propagating the Remcos Remote Access Trojan (RAT), an advanced and potent malware strain. CERT-UA attributes this campaign to a different threat actor, UAC-0050, further highlighting the complexity and diversity of cyber threats faced by Ukraine.

UAC-0099 poses a significant threat to Ukraine, targeting both state organizations and employees working for companies outside of the country. Their use of sophisticated attack techniques, including the exploitation of high-severity vulnerabilities, highlights the need for enhanced cybersecurity measures. Organizations and individuals should remain vigilant to avoid falling victim to these deceptive tactics, which continue to evolve and adapt. The collaboration between cybersecurity agencies like CERT-UA and the dissemination of threat intelligence play a crucial role in mitigating the impact of such threats and protecting critical infrastructure.

Explore more

How Did Microsoft Migrate 70TB to SAP S/4HANA Private Cloud?

Managing the financial heartbeat of a global tech giant involves processing millions of complex transactions across diverse product lines ranging from gaming to cloud services. When Microsoft decided to modernize its core financial infrastructure, it faced the monumental task of migrating a 70-terabyte SAP ERP Central Component system to the SAP S/4HANA Private Cloud. This specific environment, known as SAP

Is Your VPN Gateway an Open Door for Qilin Ransomware?

The sudden realization that a primary security perimeter has been compromised often sends shockwaves through an entire organization, especially when that perimeter is a trusted VPN gateway. When Palo Alto Networks disclosed the CVE-2026-0257 vulnerability in its GlobalProtect firewalls, the severity was immediately clear through its critical CVSS score of 9.1. This specific flaw allows unauthorized actors to bypass authentication

How Data Contracts Stop Data Pipelines From Breaking

A silent failure in a data warehouse often begins with a seemingly harmless change made by an upstream software engineering team that has no visibility into how their data is consumed. When an application developer decides to rename a field from “user_id” to “customer_uuid” or changes a data type to optimize performance, the ripple effect can be catastrophic for the

Regulators Crack Down on Predatory Digital Lending Apps

The aggressive expansion of fintech solutions across emerging markets has necessitated a sophisticated regulatory response to protect vulnerable consumers from predatory lending practices that often bypass traditional banking safeguards. As digital money lenders proliferated, many operated in a gray area, utilizing invasive data mining and psychological intimidation to ensure repayment from borrowers who found themselves trapped in cycles of high-interest

Azure DevOps Flaw Allows Attackers to Hijack AI Agents

The rapid integration of artificial intelligence into the software development lifecycle has created a sophisticated ecosystem where autonomous agents handle complex tasks like code reviews, yet a significant vulnerability within the Microsoft Azure DevOps Model Context Protocol server demonstrates that these same efficiencies can be turned against the organizations that rely on them. By exploiting a flaw in how the