• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

UAC-0099 Hackers Weaponize HTA Information to Deploy MATCHBOIL Loader Malware

Admin by Admin
August 6, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


UAC-0099 is a risk actor group that has been concentrating on state officers, protection forces, and defense-industrial companies in a sequence of subtle cyberattacks that Ukraine’s CERT-UA has been investigating.

The assaults sometimes provoke with phishing emails from UKR.NET addresses, that includes topics like “court docket summons” and hyperlinks to legit file-sharing companies, typically shortened by way of URL shorteners.

These hyperlinks result in double-archived information containing malicious HTML Utility (HTA) information.

Focusing on Ukrainian Protection

Upon execution, the HTA information deploy obfuscated VBScript that creates momentary textual content information with HEX-encoded knowledge and PowerShell code, alongside a scheduled process named “PdfOpenTask.”

This process executes the PowerShell script, which decodes the information right into a .txt file, renames it to an executable like “AnimalUpdate.exe,” and units up one other scheduled process “AnimalSoftUpdateAnimalSoftware” to make sure persistence.

MATCHBOIL Loader
Instance of an e mail and a decoy file

This chain deploys the MATCHBOIL loader, probably changing earlier variants like LONEPAGE, and facilitates the loading of extra payloads such because the MATCHWOK backdoor and DRAGSTARE stealer.

CERT-UA notes that UAC-0099’s shifting techniques, methods, and procedures underscore the group’s persistent evolution, adapting to defenses whereas sustaining a concentrate on espionage and knowledge exfiltration in Ukraine’s essential sectors.

Technical Breakdown of Malware Elements

Developed in C#, MATCHBOIL serves as a loader that gathers system fingerprints together with CPU ProcessorId by way of WMI queries (e.g., “BFEBFBFF000806EA”), BIOS SerialNumber, username, and MAC deal with concatenating them into an “SN” HTTP header for command-and-control (C2) communications.

It employs HTTP GET requests to URIs like “/articles/pictures/forest.jpg” on servers akin to geostat[.]lat, extracting payloads by way of regex patterns for “”, adopted by HEX and BASE64 decoding.

The payload is saved with a .com extension (e.g., “%LOCALAPPDATApercentDevicesMonitordevicemonitor.com”) and persevered by registry Run keys or scheduled duties like “DocumentTask.”

MATCHWOK, one other C# backdoor, executes PowerShell instructions by compiling .NET assemblies at runtime, renaming powershell.exe, and routing instructions by way of STDIN, with outcomes exfiltrated over HTTPS to C2 addresses saved in config.ini information.

Instructions are AES-256 encrypted inside

The DRAGSTARE stealer, additionally in C#, collects intensive system knowledge pc identify, OS model, RAM, disk particulars, community interfaces, ARP tables, and lively TCP connections whereas stealing browser credentials from Chrome and Mozilla by way of DPAPI decryption of information like logins.json.

It recursively scans directories like Desktop and Downloads for file sorts akin to .docx, .pdf, and .ovpn, archiving them in ZIP format for exfiltration from staging folders like “%LOCALAPPDATApercentNordDragonScan.”

Anti-VM checks and registry-based persistence by way of keys like ‘NordStar’ improve evasion. C2 interactions contain encrypted, BASE64-encoded requests to static URLs, with flag information (e.g., “s1.txt” for system data assortment) marking operational levels.

These instruments spotlight UAC-0099’s modular method, mixing loaders, backdoors, and stealers for sustained entry and knowledge theft.

Indicators of Compromise (IOCs)

Class Examples
Information d24d29e814f275f4432ba9c61e327e41 (Summons-756_840_25.rar), 059da876312f83c5d11aeb7035eb7feb (AnimalUpdate.exe – MATCHBOIL), 17f3df06950610ebc7c9f4918ece6e78 (devicemonitor.com – MATCHWOK), %LOCALAPPDATApercentNordDragonScans1.txt
Hosts %TMPpercentdocumenttemp.txt, C:UsersPublicDownloadsAnimalUpdate.exe, HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun’UpdateMonitor’, schtasks.exe /create /tn PdfOpenTask /tr “powershell.exe …”
Community court docket.ics3312@ukr[.]internet, 64[.]95.10.117, hXXps://geostat[.]lat/articles/pictures/forest.jpg, egyptanimals[.]com, secfileshare[.]com

The Final SOC-as-a-Service Pricing Information for 2025– Obtain for Free

Tags: .HTADeployfilesHackersLoaderMalwareMATCHBOILUAC0099Weaponize
Admin

Admin

Next Post
Genie 3: A brand new frontier for world fashions

Genie 3: A brand new frontier for world fashions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025
Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

By no means one to lag behind HSR and ZZZ, Genshin Influence will introduce its personal new pink-haired animal-themed woman in Model Luna 6

By no means one to lag behind HSR and ZZZ, Genshin Influence will introduce its personal new pink-haired animal-themed woman in Model Luna 6

March 28, 2026
Iran-Linked Handala Hackers Breach FBI Chief Kash Patel’s Gmail

Iran-Linked Handala Hackers Breach FBI Chief Kash Patel’s Gmail

March 28, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved