logo

UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware

ID: dbbfa8c0-661c-5ede-ad47-e6188f94bd41

STIX ID: report--dbbfa8c0-661c-5ede-ad47-e6188f94bd41

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2023-12-22

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** The report describes UAC-0099 conducting targeted phishing campaigns against Ukrainian-linked employees that leverage multiple infection chains—including HTA attachments, self-extracting archives with malicious LNK files, and WinRARZIP exploitation of CVE-2023-38831—to deploy LONEPAGE VBS which contacts C2 to fetch additional payloads such as keyloggers, stealers, and screenshot tools; actors use PowerShell and scheduled tasks for execution and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.