#MATCHBOIL
The analyzed VBS script is part of the toolset of UAC-0099, a group typically targeting transportation and energy sectors. The script's original purpose is to download and install MATCHBOIL, malware used exclusively by this group. CERT-UA documented it: cert.gov.ua/article/6318... 3/3
CERT-UA
Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.
cert.gov.ua
August 27, 2026 at 8:01 AM
Detect UAC-0099 attacks against Ukraine using MATCHBOIL, MATCHWOK, and DRAGSTARE malware with curated Sigma rules from SOC Prime Platform.
socprime.com/blog/detect-...
UAC-0099 Attack Detection: Hackers Target Government and Defense Agencies in Ukraine Using MATCHBOIL, MATCHWOK, and DRAGSTARE Malware | SOC Prime
Detect UAC-0099 attacks against Ukraine using MATCHBOIL, MATCHWOK, and DRAGSTARE malware with curated Sigma rules from SOC Prime Platform.
socprime.com
August 7, 2025 at 11:45 AM
One attempt, not a proven campaign

ESET saw a UAC-0099 VBS comment aimed at stopping an LLM scanner before MATCHBOIL. It did not affect runtime behavior, and public reporting does not show campaign-scale success.
September 11, 2026 at 1:51 PM
UAC-0099は、偽のNotepad++プラグインの中にマルウェアを隠してウクライナの組織を標的にしている。

CERT-UAは、少なくとも2022年半ばから活動しているロシア系の脅威アクターであるUAC-0099によるフィッシングキャンペーンに関する新たな勧告を発表しました。UAC-0099は、 WinRARの脆弱性を悪用し、フィッシングメールを使用してLONEPAGE、MATCHBOIL、DRAGSTAREなどのマルウェアファミリーを配信することで知られています。

今夏初めに確認された最新の攻撃キャンペーンでは、トロイの木馬化されたNotepad++プラグインが感染メカニズムとし...
UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations
UAC-0099 delivers malware via a fake Notepad++ plugin, using a loader that sabotages itself if run without the correct arguments.
securityaffairs.com
August 24, 2026 at 12:36 PM
📢 UAC-0099 : nouveaux outils LUNCHPOKE, BURNYBEAR et MATCHBOIL.V2 via DLL hijacking Notepad++
📝 ## 🔍 Contexte

Le **CERT-UA** a publié le 21 juille…
https://cyberveille.ch/posts/2026-07-24-uac-0099-nouveaux-outils-lunchpoke-burnybear-et-matchboil-v2-via-dll-hijacking-notepad/ #BURNYBEAR #Cyberveille
July 26, 2026 at 8:00 PM
CERT-UA reports a fake Notepad++ plugin delivering MATCHBOIL.V2 malware, linked to Russia-aligned UAC-0099. #CyberSecurity #Malware #Notepad++ #UAC0099 #MATCHBOIL #CERTUA thedailytechfeed.com/fake-notepad...
July 24, 2026 at 7:41 AM
UAC-0099 Is Hiding MATCHBOIL.V2 Inside Fake Notepad++ Plugins — Audit Your Extensions Now

https://blindthoughts.com/uac-0099-matchboil-v2-fake-notepad-plugin

#malware #windows #threatintelligence #certua #notepadplusplus
July 24, 2026 at 7:17 AM
🚨 Security Alert: Notepad++ is being weaponized by hackers to silently install malware on Windows machines.

The UAC-0099 threat group is using a legitimate Notepad++ 8.8.3 executable to sideload malicious DLLs (LunchPoke), eventually deploying the MatchBoil V2 loader.

🛠️ Action required:
Update...
Hackers weaponize Notepad++ plugins to deploy MatchBoil V2 malware
🚨 Security Alert: Notepad++ is being weaponized by hackers to silently install malware on Windows machines. The UAC-0099 threat group is using a legitimate Notepad++ 8.8.3 executable to sideload mali
www.alextech.ai
July 24, 2026 at 6:54 AM
A disputed Notepad++ non-issue just became a live weapon - UAC-0099 hides malware in a trusted editor. https://intel.threadlinqs.com/threat/TL-2026-1657 #ThreatIntel #CVE_2025_56383 #LunchPoke #BurnyBear
July 23, 2026 at 4:55 PM
ウクライナの政府や軍を狙ったサイバースパイ活動が確認された。2022年から活動しているハッカーグループUAC-0099が、マルウェアMatchboil等を使用。戦術は進化し続けている。 therecord.media/hackers-usin...
Hackers using fake summonses in attacks on Ukraine's defense sector
Hackers have been sending fake summons emails purportedly from Ukrainian courts to target the country’s military and defense, cyber authorities have found.
therecord.media
August 6, 2025 at 2:51 PM
CERT-UA warns of UAC-0099 phishing attacks targeting Ukraine’s defense sector
CERT-UA warns of UAC-0099 phishing attacks targeting Ukraine’s defense sector
Ukraine's CERT-UA warns of phishing attacks by UAC-0099 targeting defense sectors, using malware like MATCHBOIL, MATCHWOK, and DRAGSTARE.
securityaffairs.com
August 7, 2025 at 10:49 AM
UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware
UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware
cybersecuritynews.com
August 6, 2025 at 3:38 PM
CERT-UA warns of UAC-0099 phishing attacks targeting Ukraine’s defense sector

Ukraine’s CERT-UA warns of phishing attacks by UAC-0099 targeting defense sectors, using malware like MATCHBOIL, MATCHWOK, and DRAGSTARE. Ukraine’s CERT-UA warns of phishing attacks by threat actor UAC…

#hackernews #news
CERT-UA warns of UAC-0099 phishing attacks targeting Ukraine’s defense sector
Ukraine’s CERT-UA warns of phishing attacks by UAC-0099 targeting defense sectors, using malware like MATCHBOIL, MATCHWOK, and DRAGSTARE. Ukraine’s CERT-UA warns of phishing attacks by threat actor UAC-0099 targeting government and defense sectors, delivering malware like MATCHBOIL and DRAGSTARE. The National Cyber Incident, Cyber Attack, and Cyber Threat Response Team CERT-UA investigated multiple attacks against […]
securityaffairs.com
August 8, 2025 at 8:56 AM
CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks carried out by a threat actor called UAC-0099 targeting government agencies, the defense forces, and enterprises of t…

#hackernews #news
CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks carried out by a threat actor called UAC-0099 targeting government agencies, the defense forces, and enterprises of the defense-industrial complex in the country. The attacks, which leverage phishing emails as an initial compromise vector, are used to deliver malware families like MATCHBOIL, MATCHWOK, and
thehackernews.com
August 7, 2025 at 2:31 AM
Phishing on the Frontlines: How UAC-0099 Targets Ukraine’s Government and Defense with Sophisticated Malware

In a relentless wave of cyberattacks, the Ukrainian National Cybersecurity team CERT-UA has uncovered a highly sophisticated phishing campaign targeting government agencies, military…
Phishing on the Frontlines: How UAC-0099 Targets Ukraine’s Government and Defense with Sophisticated Malware
In a relentless wave of cyberattacks, the Ukrainian National Cybersecurity team CERT-UA has uncovered a highly sophisticated phishing campaign targeting government agencies, military forces, and defense industry enterprises. The threat actor behind this campaign, known as UAC-0099, is employing advanced malware strains such as MATCHBOIL, MATCHWOK, and DRAGSTARE to infiltrate and maintain persistent control over critical systems. This operation not only underscores the rising cyber warfare tensions in the ongoing Ukraine conflict but also highlights the evolving complexity of modern cyber threats aimed at state-level targets.
undercodenews.com
August 8, 2025 at 8:43 AM
UAC-0099 Hackers Weaponizing HTA Files To Deliver MATCHBOIL Loader Malware https://packetstorm.news/news/view/38387 #news
August 6, 2025 at 4:21 PM
📌 CERT-UA Warns of HTA-Delivered Cyber Attacks Targeting Ukrainian Government and Defense Sectors https://www.cyberhub.blog/article/11305-cert-ua-warns-of-hta-delivered-cyber-attacks-targeting-ukrainian-government-and-defense-sectors
CERT-UA Warns of HTA-Delivered Cyber Attacks Targeting Ukrainian Government and Defense Sectors
CERT-UA has warned of cyber attacks by UAC-0099 targeting Ukrainian government and defense sectors. The attacks use phishing emails with malicious HTA files disguised as court summons. These HTA files execute C# scripts to deploy malware like MATCHBOIL and MATCHWOK. HTA files are dangerous as they run with user-level permissions, making them effective for malware delivery. The use of C# scripts adds complexity to detection efforts. The targeting of government and defense entities suggests potential state sponsorship. These attacks highlight the evolving tactics of threat actors, emphasizing the need for robust email security, endpoint protection, and user awareness training. Organizations should monitor for unusual C# script executions and implement systems to detect and block malicious HTA files.
www.cyberhub.blog
August 9, 2025 at 12:00 AM
📌 CERT-UA Warns of UAC-0099 Phishing Attacks Targeting Ukraine's Defense Sector https://www.cyberhub.blog/article/11275-cert-ua-warns-of-uac-0099-phishing-attacks-targeting-ukraines-defense-sector
CERT-UA Warns of UAC-0099 Phishing Attacks Targeting Ukraine's Defense Sector
The Computer Emergency Response Team of Ukraine (CERT-UA) has issued a warning about a series of phishing attacks conducted by the threat actor UAC-0099. These attacks are targeting government and defense sectors in Ukraine, utilizing custom malware strains such as MATCHBOIL, MATCHWOK, and DRAGSTARE. According to the report, UAC-0099 has been observed using phishing emails to deliver malicious payloads. The malware strains mentioned are designed for various malicious activities, including data exfiltration and remote access. MATCHBOIL, for instance, is known for its ability to evade detection by traditional antivirus solutions, while DRAGSTARE is often used for lateral movement within a compromised network. The technical implications of these attacks are significant. The use of phishing as an initial access vector highlights the importance of robust email security measures. Organizations should prioritize employee training on recognizing phishing attempts, implement multi-factor authentication, and deploy advanced threat detection systems. The impact on the cybersecurity landscape is profound. These attacks are part of a broader pattern of cyber warfare between Russia and Ukraine, with state-sponsored actors continuously evolving their tactics. For cybersecurity professionals, this underscores the importance of continuous monitoring and threat intelligence sharing. In conclusion, the UAC-0099 phishing attacks targeting Ukraine's defense sector are a stark reminder of the persistent and evolving threats in the cyber domain. Cybersecurity professionals must remain vigilant and proactive in their defense strategies.
www.cyberhub.blog
August 8, 2025 at 1:00 PM
CERT-UA has issued a warning about UAC-0099, a threat actor targeting Ukrainian government and defense sectors with phishing emails that deliver malware like MATCHBOIL, MATCHWOK, and DRAGSTARE.
CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures
thehackernews.com
August 6, 2025 at 3:03 PM
CERT-UA warns of UAC-0099 phishing attacks targeting Ukraine’s defense sector
CERT-UA warns of UAC-0099 phishing attacks targeting Ukraine’s defense sector
Ukraine's CERT-UA warns of phishing attacks by UAC-0099 targeting defense sectors, using malware like MATCHBOIL, MATCHWOK, and DRAGSTARE.
ift.tt
August 11, 2025 at 11:12 AM
CERT-UA segnala attacchi phishing con HTA che diffondono malware C# in Ucraina, colpendo governi e difesa per furto dati sensibili.

#CERTUA #DRAGSTARE #evidenza #HTA #malware #MATCHBOIL #phishing #UAC0099
www.matricedigitale.it/2025/08/06/u...
August 6, 2025 at 10:45 AM
CERT-UA warns of UAC-0099 phishing attacks targeting Ukraine’s defense sector Ukraine’s CERT-UA warns of phishing attacks by UAC-0099 targeting defense sectors, using malware like MATCHBOIL, MA...

#APT #Breaking #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Cyber #warfare #Hacking #Malware […]

[Original post on securityaffairs.com]
Original post on securityaffairs.com
securityaffairs.com
August 7, 2025 at 11:08 AM