Ukrainian Threat Actor UAC-0099 Continues Targeted Attacks: An In-Depth Analysis

The threat actor known as UAC-0099 has been linked to a series of persistent attacks directed at Ukraine, with a particular focus on Ukrainian employees working for companies outside of the country. This article provides an in-depth analysis of the tactics employed by UAC-0099, including the exploitation of a high-severity flaw in the widely used WinRAR software.

Background of UAC-0099

UAC-0099 first came to the attention of the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2023. The team documented the threat actor’s attacks against state organizations and media entities, with the primary motive believed to be espionage. These attacks marked the onset of UAC-0099’s activities and the subsequent evolution of their techniques.

Attack Techniques Used by UAC-0099

UAC-0099 has employed a variety of attack techniques to infiltrate target systems. One prominent method involves the use of phishing messages containing various file attachments, including HTA, RAR, and LNK files. These attachments, upon interaction, deploy a malware strain called LONEPAGE, which is used by UAC-0099 to gain control over compromised systems. A noteworthy aspect of this technique is the exploitation of a high-severity vulnerability (CVE-2023-38831) present in WinRAR, allowing for the distribution of LONEPAGE through ZIP files.

Detailed Analysis of Attack Techniques

UAC-0099 employs a clever disguise by using an SFX file that houses an LNK shortcut. This shortcut poses as a DOCX file related to a court summons, utilizing the icon for Microsoft WordPad in an attempt to entice the victim into opening it. Once accessed, malicious PowerShell code is executed, leading to the installation of the LONEPAGE malware.

Another attack method utilized by UAC-0099 involves the creation of a specially crafted ZIP archive susceptible to the aforementioned WinRAR vulnerability (CVE-2023-38831). When targeted individuals interact with these ZIP archives, the vulnerability is exploited, resulting in the installation of the LONEPAGE malware.

Analysis of UAC-0099’s Tactics

The tactics employed by UAC-0099 are characterized by their simplicity and effectiveness. By leveraging well-known vulnerabilities, disguising malicious files, and utilizing social engineering techniques through phishing messages, UAC-0099 is successful in infiltrating target systems. Despite the various initial infection vectors, the core infection remains consistent, relying on PowerShell and the creation of a scheduled task that executes a VBScript (VBS) file.

Warning from CERT-UA Regarding New Phishing Campaign

CERT-UA has recently issued a warning regarding a new wave of phishing messages claiming outstanding Kyivstar dues. These messages serve as a vehicle for propagating the Remcos Remote Access Trojan (RAT), an advanced and potent malware strain. CERT-UA attributes this campaign to a different threat actor, UAC-0050, further highlighting the complexity and diversity of cyber threats faced by Ukraine.

UAC-0099 poses a significant threat to Ukraine, targeting both state organizations and employees working for companies outside of the country. Their use of sophisticated attack techniques, including the exploitation of high-severity vulnerabilities, highlights the need for enhanced cybersecurity measures. Organizations and individuals should remain vigilant to avoid falling victim to these deceptive tactics, which continue to evolve and adapt. The collaboration between cybersecurity agencies like CERT-UA and the dissemination of threat intelligence play a crucial role in mitigating the impact of such threats and protecting critical infrastructure.

Explore more

Why Use the Exclude Strategy for Business Central Permissions?

Navigating the labyrinthine complexities of enterprise resource planning security often forces administrators to choose between total system chaos and a paralyzing administrative nightmare. Within the ecosystem of Microsoft Dynamics 365 Business Central, this struggle usually manifests as a tug-of-war between accessibility and control. Most organizations find themselves trapped in a traditional model where every single access right must be hand-picked

Lenovo Legion Y70 Smartphone – Review

The competitive mobile gaming landscape has undergone a radical transformation recently, leaving enthusiasts questioning if any brand could challenge the dominant players currently controlling the high-end market. Lenovo has answered this by resurrecting a dormant giant from its four-year hiatus. The Legion Y70 represents a calculated attempt to reclaim lost ground by blending extreme performance with a newly refined aesthetic

Can Traditional IAM Keep Up with Autonomous AI Agents?

Digital entities are now navigating the intricate web of corporate infrastructure with a degree of autonomy that renders conventional login credentials and firewall rules virtually obsolete. Enterprise developers are deploying autonomous AI agents at a pace that far outstrips the evolution of corporate security protocols. These digital entities are no longer just chatbots; they are sophisticated actors capable of executing

Browser Built-In AI APIs – Review

The traditional architecture of the internet relies on a constant, expensive tether to massive server farms, yet a quiet revolution is moving that intelligence directly into the browser window itself. For years, integrating large language models into web applications required complex server-side pipelines or massive client-side JavaScript libraries that bogged down performance. The emergence of built-in AI APIs within Chromium-based

Agentic Coding Systems – Review

The transition from manually typing every semicolon to commanding autonomous agents signals the most profound shift in labor since the industrial revolution began to mechanize physical production. For decades, software engineering remained a craft defined by the granular mastery of syntax and the painstaking navigation of logic errors. The rise of agentic coding systems, however, marks a departure from this