logo

UAC-0099__2023__Deepinstinct_TA-UAC-0099-Continues-Target-Ukraine_12-21-2023.pdf

ID: c9ba8d18-e8f3-4041-9522-cd995e450b97

STIX ID: report--c9ba8d18-e8f3-4041-9522-cd995e450b97

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2024-01-03

Last Modified Date: 2024-01-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Threat actor UAC-0099 has repeatedly targeted Ukraine since 2022, deploying multi-vector campaigns that abuse SFX archives with LNK files, HTA and WinRAR exploits, and CVE-2023-38831 to drop PowerShell-based payloads and a LonePage VBS component. The campaigns use decoy court summons in Word, PDF, and ZIP formats to lure victims and exfiltrate host information to hardcoded C2 servers; IOCs include several IPs and C2 domains, with ongoing activity as of late 2023.