UAC-0099
UAC-0099 is a threat actor that has been active since at least May 2023, targeting Ukrainian entities. They have been observed using a known WinRAR vulnerability to carry out attacks, indicating a level of sophistication. The actor relies on PowerShell and the creation of scheduled tasks to execute malicious VBS files for initial infection. Monitoring and limiting the functionality of these… Source: MISP
Activity on Jábega · 12 weeks
1 stories · first seen on 8 Oct 2026 · last seen on 8 Oct 2026
News
- UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTMLThe Hacker News · 8 Oct 2026
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy and SigmaHQ.