Listen to this Post

⚠️ Introduction: A Digital Battlefield
Ukraine’s cyber landscape continues to reel from relentless digital warfare. As geopolitical tensions escalate, so do the efforts of state-aligned threat actors to breach critical systems. Two major players—UAC-0099 and Gamaredon—have intensified their cyber espionage activities, specifically targeting Ukrainian government agencies, military forces, and defense contractors. With a mix of advanced phishing techniques and custom malware, these threat actors are weaponizing the internet to exfiltrate sensitive data, gain persistent access, and disrupt national security operations. The latest findings from CERT-UA and ESET paint a troubling picture of modern cyberwarfare in Eastern Europe.
🧠 the Original Findings
The Ukrainian Computer Emergency Response Team (CERT-UA) has issued a stark warning regarding UAC-0099, a persistent cyber threat actor known for targeting Ukrainian defense infrastructure. The latest campaign centers on phishing attacks, using deceptive court summons emails embedded with shortened URLs via services like Cuttly. These links direct victims to double-archived packages containing a malicious HTA file. When opened, the HTA executes obfuscated VBScript, which sets up scheduled tasks to ensure persistence and launches a C-based loader named MATCHBOIL.
MATCHBOIL, in turn, drops two malware strains:
MATCHWOK: A backdoor capable of executing PowerShell commands and relaying results to external servers.
DRAGSTARE: A data stealer designed to harvest browser data, sensitive documents (.docx, .xls, .pdf, etc.), screenshots, and execute attacker-sent PowerShell commands.
CERT-UA originally identified UAC-0099 in June 2023, previously exploiting WinRAR vulnerability CVE-2023-38831 to distribute a separate malware named LONEPAGE.
Meanwhile, cybersecurity firm ESET has released a damning report on Gamaredon, a Russian-aligned threat group. In 2024, Gamaredon launched relentless spearphishing campaigns, deploying six new malware tools tailored for stealth and persistence:
PteroDespair: Reconnaissance via PowerShell
PteroTickle: Lateral movement by targeting Python executables
PteroGraphin: Establishes persistence through Excel add-ins and encrypted payload delivery
PteroStew: VBScript downloader using alternate data streams
PteroQuark: A new VBScript-based component
PteroBox: File stealer exfiltrating to Dropbox
Gamaredon’s operations feature fast-flux DNS, HTML smuggling, and use of legitimate services like Telegram and Cloudflare tunnels to hide C2 infrastructure. ESET warns that despite retiring some old tools, Gamaredon’s aggressive evolution and evasion techniques make it a formidable cyber adversary.
🔍 What Undercode Say:
Threat Actor Tactics: A Deep Dive
From a technical perspective, both UAC-0099 and Gamaredon are deploying increasingly complex multi-stage attack chains. They begin with a social engineering hook—typically spearphishing emails laced with urgency (like court summons)—which is an emotional trigger for fast clicks.
Their payload delivery mechanisms rely heavily on HTML Applications (HTA) and Visual Basic Scripts, a combination that’s both lightweight and effective for bypassing basic email defenses. The malware is well-structured: initial payloads like MATCHBOIL act as loaders, which then dynamically fetch more specialized malware like MATCHWOK (for backdoor access) and DRAGSTARE (for data exfiltration).
Tools for Persistence and Evasion
Gamaredon is redefining persistence and stealth by:
Using alternate data streams to hide malware in innocent files
Employing legitimate services like Dropbox, Codeberg, and Cloudflare to mask outbound traffic
Leveraging PowerShell-based frameworks, making detection difficult due to PowerShell’s deep integration into Windows systems
The Ptero toolset represents a new phase in their strategy—where persistence, stealth, and modular infection chains intersect. Tools like PteroGraphin allow the attackers to create encrypted communication channels, making it harder for defenders to spot outbound connections.
Targets and Intent
These campaigns are not random. They clearly target defense-related institutions, government infrastructure, and industrial complexes. This indicates the attacks are not financially motivated (unlike ransomware), but are purely strategic, aimed at surveillance, disruption, and long-term compromise.
The malware’s data exfiltration capabilities are tailored for espionage—collecting sensitive docs, VPN configs, and RDP credentials. The inclusion of screenshot capture and command execution functions shows the attackers want real-time intelligence.
✅ Fact Checker Results 🕵️♂️
CERT-UA and ESET are reputable national and international cyber intelligence bodies.
CVE-2023-38831 is a confirmed vulnerability in WinRAR, widely reported.
Gamaredon’s use of fast-flux DNS and Telegram API has been independently documented by other security vendors.
🔮 Prediction 🔥
Expect increased cyber aggression from both UAC-0099 and Gamaredon throughout late 2025. These actors are likely to:
Refine phishing tactics with more personalized lures (government forms, military orders).
Adopt AI-generated malware with polymorphic capabilities to evade detection.
Target energy, logistics, and satellite communication sectors to extend operational disruption.
As Ukraine continues its defense, cyber resilience strategies—including sandboxing, endpoint detection and response (EDR), and zero-trust policies—will become more critical than ever.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: thehackernews.com
Extra Source Hub:
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




