The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of attacks carried out by a threat actor called UAC-0099, which targets government agencies, the armed forces, and enterprises of the defense-industrial complex in the country.
See also: Bing results spread Bumblebee malware

The attacks exploit phishing emails as the initial means of compromise to deliver malware families such as MATCHBOIL, MATCHWOK , and DRAGSTARE.
UAC-0099, which was first publicly documented by the organization in June 2023, has a history of targeting Ukrainian entities for espionage purposes. Previous attacks have been observed exploiting security vulnerabilities in the WinRAR software (CVE-2023-38831, CVSS score: 7.8) to spread a malware called LONEPAGE.
The latest infection chain involves using bait emails related to court summonses to entice recipients to click on links shortened using URL such as Cuttly. These links, sent via UKR.NET, lead to a duplicate archive file containing an HTML Application (HTA).
Execution of the HTA payload triggers the launch of an obfuscated Visual Basic Script (VBScript) file that creates a scheduled task for persistence and ultimately executes a loader called MATCHBOIL, a C#-based program designed to drop additional malware onto the computer.
This includes a backdoor called MATCHWOK and a stealer called DRAGSTARE. Also written using the C# programming language, MATCHWOK is capable of executing PowerShell commands and transferring the results of the execution to a remote server.
DRAGSTARE is equipped to collect system information, data from web browsers, files matching a specific list of extensions (“.docx”, “.doc”, “.xls”, “.txt”, “.ovpn”, “.rdp”, “.txt” and “.pdf”) from the “Desktop”, “Documents”, “Downloads” folders, screenshots and executed PowerShell commands received from an attacker-controlled server.
See also: Raven Stealer malware steals login credentials
The revelation comes just over a month after ESET published a detailed report documenting Gamaredon's "relentless" spear-phishing attacks against Ukrainian entities in 2024, describing the use of six new malware tools designed for stealth, persistence, and lateral movement:

– PteroDespair, a PowerShell reconnaissance tool for collecting diagnostic data about previously deployed malware.
– PteroTickle, a PowerShell tool that targets Python applications that have been converted to executables on fixed and removable drives to facilitate lateral movement by injecting code that likely serves PteroPSLoad or another PowerShell downloader.
– PteroGraphin, a PowerShell tool for establishing persistence using Microsoft Excel add-ins and scheduled tasks, as well as creating an encrypted communication channel for payload delivery via the Telegraph API.
– PteroStew, a VBScript downloader that stores its code in alternate data streams associated with benign files on the victim’s system.
– PteroQuark, a VBScript downloader that is introduced as a new component within the VBScript version of the PteroLNK tool.
– PteroBox, a PowerShell file stealer that is similar to PteroPSDoor but exports stolen files to Dropbox.
“Gamaredon’s spear-phishing activities intensified significantly in the second half of 2024,” said security researcher Zoltán Rusnák. “Campaigns typically lasted from one to five consecutive days, with emails containing malicious archive files (RAR, ZIP, 7z) or XHTML files using HTML smuggling techniques.”
Attacks often result in the delivery of malicious HTA or LNK files that execute embedded VBScript downloaders such as PteroSand, along with the distribution of updated versions of its existing tools such as PteroPSDoor, PteroLNK, PteroVDoor , and PteroPSLoad.
See also: Hackers introduced infostealer malware into a game on Steam
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Other notable aspects of the Russian-aligned threat actor's technique include the use of fast-flux DNS techniques and reliance on legitimate third-party services like Telegram.
