{"id":5330,"date":"2025-08-06T17:24:56","date_gmt":"2025-08-06T17:24:56","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=5330"},"modified":"2025-08-06T17:24:56","modified_gmt":"2025-08-06T17:24:56","slug":"uac-0099-hackers-weaponize-hta-information-to-deploy-matchboil-loader-malware","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=5330","title":{"rendered":"UAC-0099 Hackers Weaponize HTA Information to Deploy MATCHBOIL Loader Malware"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>UAC-0099 is a risk actor group that has been concentrating on state officers, protection forces, and defense-industrial companies in a sequence of subtle cyberattacks that Ukraine\u2019s CERT-UA has been investigating.<\/p>\n<p>The assaults sometimes provoke with phishing emails from UKR.NET addresses, that includes topics like \u201ccourt docket summons\u201d and hyperlinks to legit file-sharing companies, typically shortened by way of URL shorteners. <\/p>\n<p>These hyperlinks result in double-archived information containing malicious HTML Utility (HTA) information. <\/p>\n<h2 class=\"wp-block-heading\" id=\"h-targeting-ukrainian-defense\"><strong>Focusing on Ukrainian Protection <\/strong><\/h2>\n<p>Upon execution, the HTA information deploy obfuscated VBScript that creates momentary textual content information with HEX-encoded knowledge and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/new-clearfake-variant-uses-fake-recaptcha\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell code<\/a>, alongside a scheduled process named \u201cPdfOpenTask.\u201d <\/p>\n<p>This process executes the PowerShell script, which decodes the information right into a .txt file, renames it to an executable like \u201cAnimalUpdate.exe,\u201d and units up one other scheduled process \u201cAnimalSoftUpdateAnimalSoftware\u201d to make sure persistence. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiNmrxho0QviIqzCbAraELgsnmCQBo8Us6IpyhIwQuB7osimhyz7WPBnxYXmetGTWK-jnqYj12tqB_lDS6ch51nyYWkuo7hg8zzQrP8q2xR9CrAWIZ7Pq52M2PsU_Y99-DgX_Z9fvrOQGLytZjnDVYN9KTtxKe1eNrobuSlh3XcwdzItC-Qe-uCRMw5Ar4\/s16000\/Example%20of%20an%20email%20and%20a%20decoy%20file.webp\" alt=\"MATCHBOIL Loader\"\/><figcaption class=\"wp-element-caption\">Instance of an e mail and a decoy file<\/figcaption><\/figure>\n<\/div>\n<p>This chain deploys the MATCHBOIL loader, probably changing earlier variants like LONEPAGE, and facilitates the loading of extra payloads such because the MATCHWOK backdoor and DRAGSTARE stealer. <\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cert.gov.ua\/article\/6284949\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CERT-UA notes<\/a> that UAC-0099\u2019s shifting techniques, methods, and procedures underscore the group\u2019s persistent evolution, adapting to defenses whereas sustaining a concentrate on espionage and knowledge exfiltration in Ukraine\u2019s essential sectors.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-breakdown-of-malware-components\"><strong>Technical Breakdown of Malware Elements<\/strong><\/h2>\n<p>Developed in C#, MATCHBOIL serves as a loader that gathers system fingerprints together with CPU ProcessorId by way of WMI queries (e.g., \u201cBFEBFBFF000806EA\u201d), BIOS SerialNumber, username, and MAC deal with concatenating them into an \u201cSN\u201d HTTP header for command-and-control (C2) communications. <\/p>\n<p>It employs HTTP GET requests to URIs like \u201c\/articles\/pictures\/forest.jpg\u201d on servers akin to geostat[.]lat, extracting payloads by way of regex patterns for \u201c<script><![CDATA[(.*?)]]><\/script>\u201d, adopted by HEX and BASE64 decoding. <\/p>\n<p>The payload is saved with a .com extension (e.g., \u201c%LOCALAPPDATApercentDevicesMonitordevicemonitor.com\u201d) and persevered by registry Run keys or scheduled duties like \u201cDocumentTask.\u201d <\/p>\n<p>MATCHWOK, one other C# backdoor, executes PowerShell instructions by compiling .NET assemblies at runtime, renaming powershell.exe, and routing instructions by way of STDIN, with outcomes exfiltrated over HTTPS to C2 addresses saved in config.ini information. <\/p>\n<p>Instructions are AES-256 encrypted inside <script><![CDATA[ tags, and anti-analysis checks detect tools like Wireshark or OllyDbg. ]]><\/script><\/p>\n<p>The DRAGSTARE stealer, additionally in C#, collects intensive system knowledge pc identify, OS model, RAM, disk particulars, community interfaces, ARP tables, and lively TCP connections whereas stealing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/trox-stealer-harvests-sensitive-data-including-stored-credit-cards\/\" target=\"_blank\" rel=\"noreferrer noopener\">browser credentials<\/a> from Chrome and Mozilla by way of DPAPI decryption of information like logins.json. <\/p>\n<p>It recursively scans directories like Desktop and Downloads for file sorts akin to .docx, .pdf, and .ovpn, archiving them in ZIP format for exfiltration from staging folders like \u201c%LOCALAPPDATApercentNordDragonScan.\u201d <\/p>\n<p>Anti-VM checks and registry-based persistence by way of keys like \u2018NordStar\u2019 improve evasion. C2 interactions contain encrypted, BASE64-encoded requests to static URLs, with flag information (e.g., \u201cs1.txt\u201d for system data assortment) marking operational levels. <\/p>\n<p>These instruments spotlight UAC-0099\u2019s modular method, mixing loaders, backdoors, and stealers for sustained entry and knowledge theft.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IOCs)<\/strong><\/h2>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Class<\/th>\n<th>Examples<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Information<\/td>\n<td>d24d29e814f275f4432ba9c61e327e41 (Summons-756_840_25.rar), 059da876312f83c5d11aeb7035eb7feb (AnimalUpdate.exe \u2013 MATCHBOIL), 17f3df06950610ebc7c9f4918ece6e78 (devicemonitor.com \u2013 MATCHWOK), %LOCALAPPDATApercentNordDragonScans1.txt<\/td>\n<\/tr>\n<tr>\n<td>Hosts<\/td>\n<td>%TMPpercentdocumenttemp.txt, C:UsersPublicDownloadsAnimalUpdate.exe, HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun\u2019UpdateMonitor\u2019, schtasks.exe \/create \/tn PdfOpenTask \/tr \u201cpowershell.exe \u2026\u201d<\/td>\n<\/tr>\n<tr>\n<td>Community<\/td>\n<td>court docket.ics3312@ukr[.]internet, 64[.]95.10.117, hXXps:\/\/geostat[.]lat\/articles\/pictures\/forest.jpg, egyptanimals[.]com, secfileshare[.]com<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><code><strong>The Final SOC-as-a-Service Pricing Information for 2025<\/strong><\/code><\/strong>\u2013\u00a0<strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/underdefense.com\/guides\/soc-as-a-service-pricing-guide\/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_socaas_price_aug\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Obtain for Free<\/a><\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>UAC-0099 is a risk actor group that has been concentrating on state officers, protection forces, and defense-industrial companies in a sequence of subtle cyberattacks that Ukraine\u2019s CERT-UA has been investigating. The assaults sometimes provoke with phishing emails from UKR.NET addresses, that includes topics like \u201ccourt docket summons\u201d and hyperlinks to legit file-sharing companies, typically shortened [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5332,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[4266,2309,129,554,4527,216,4526,4525,555],"class_list":["post-5330","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-hta","tag-deploy","tag-files","tag-hackers","tag-loader","tag-malware","tag-matchboil","tag-uac0099","tag-weaponize"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5330","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5330"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5330\/revisions"}],"predecessor-version":[{"id":5331,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5330\/revisions\/5331"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/5332"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-12 05:08:38 UTC -->