UAC-0099

First seen
2023-05-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
nation-state
Profile updated
2026-07-07 12:11:37

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

UAC-0099 is a threat actor that has been active since at least May 2023, targeting Ukrainian entities. They have been observed using a known WinRAR vulnerability to carry out attacks, indicating a level of sophistication. The actor relies on PowerShell and the creation of scheduled tasks to execute malicious VBS files for initial infection. Monitoring and limiting the functionality of these components can help mitigate the risk of UAC-0099 attacks.

Reports & references

  • CERT-UA — 4818341 (report)
  • deepinstinct.com — Threat Actor Uac 0099 Continues To Target Ukraine (report)

External references