UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware
ID: dbbfa8c0-661c-5ede-ad47-e6188f94bd41
STIX ID: report--dbbfa8c0-661c-5ede-ad47-e6188f94bd41
Feed Name: The Hacker News
Threat Score
**Executive summary:** The report describes UAC-0099 conducting targeted phishing campaigns against Ukrainian-linked employees that leverage multiple infection chains—including HTA attachments, self-extracting archives with malicious LNK files, and WinRARZIP exploitation of CVE-2023-38831—to deploy LONEPAGE VBS which contacts C2 to fetch additional payloads such as keyloggers, stealers, and screenshot tools; actors use PowerShell and scheduled tasks for execution and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
