【要点】
◎ウクライナの政府機関やメディア組織などを主な標的としてサイバースパイ活動を行う、国家支援型とみられる攻撃組織
【辞書】
◆UAC-0099 (Malpedia)
https://malpedia.caad.fkie.fraunhofer.de/actor/uac-0099
【ニュース】
■2023年
◆ウクライナを狙う脅威アクター「UAC-0099」、WinRARを悪用してサイバー攻撃 (マイナビニュース, 2023/12/28 08:47)
https://news.mynavi.jp/techplus/article/20231228-2851344/
⇒ https://malware-log.hatenablog.com/entry/2023/12/28/000000
■2025年
◇2025年11月
◆Sandworm hackers use data wipers to disrupt Ukraine's grain sector (BleepingComputer, 2025/11/06 05:01)
[サンドワームハッカー、ウクライナの穀物部門を混乱させるデータワイパーを使用]
https://www.bleepingcomputer.com/news/security/sandworm-hackers-use-data-wipers-to-disrupt-ukraines-grain-sector/
⇒ https://malware-log.hatenablog.com/entry/2025/11/06/000000
■2026年
◇2026年7月
◆Hackers abuse Notepad++ plugins to stealthily install malware (BleepingComputer, 2026/07/23 12:32)
[ハッカーがNotepad++のプラグインを悪用し、マルウェアを密かにインストールしている]
https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/
⇒ https://malware-log.hatenablog.com/entry/2026/07/23/000000_3
◆Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks (The Hacker News, 2026/07/24)
[UAC-0099攻撃において、偽のNotepad++プラグインがMATCHBOIL.V2を配布]
https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
⇒ https://malware-log.hatenablog.com/entry/2026/07/24/000000_8
【ブログ】
■2024年
◇2024年12月
◆UAC-0099攻撃の検出:WinRARエクスプロイトとLONEPAGEマルウェアを使用したウクライナ国家機関に対するサイバースパイ活動 (SOC Prime, 2024/12/16)
https://socprime.com/ja/blog/uac-0099-cyber-espionage-attacks-detection/
⇒ https://malware-log.hatenablog.com/entry/2024/12/16/000000_4
【検索】
google: UAC-0099
google:news: UAC-0099
google: site:virustotal.com UAC-0099
google: site:github.com UAC-0099
■Bing
https://www.bing.com/search?q=UAC-0099
https://www.bing.com/news/search?q=UAC-0099
https://twitter.com/search?q=%23UAC-0099
https://twitter.com/hashtag/UAC-0099
■VirusTotal
https://www.virustotal.com/gui/search/UAC-0099
【関連まとめ記事】
◆標的型攻撃組織 / APT (まとめ)
https://malware-log.hatenablog.com/entry/APT