ESET

Peter Strýček

Peter Strýček

2026

Inside a Sandworm Attack: UAC-0099 Access and a Yggdrasil-backed Backdoor

The ESET research team has been tracking Sandworm’s activities for more than a decade. In 2025 alone, we investigated more than ten incidents involving destructive malware attributed to Sandworm, most of them occurring in Ukraine. In this talk, we’ll use our first-hand experience and unique visibility into the group’s activities to explain their latest TTPs and take a deep dive into one of our recent Sandworm investigations that revealed a rarely documented collaboration between Sandworm and UAC-0099, and a very rare backdoor we named MythicRatatoskr.

Sandworm is a Russia-aligned threat actor known for conducting destructive cyberattacks against a wide range of targets, including government agencies, logistics and transportation companies, energy providers, media organizations, grain sector businesses, and telecommunications firms. These attacks typically involve the deployment of "wiper" malware designed to delete files, erase data, and render systems unbootable.

Between July and September 2025, we investigated an incident involving the targeting of a grain logistics company in Ukraine, during which the attackers carried out a data-wiping attack. During the investigation, we determined that initial access was obtained by UAC-0099 through a spear-phishing email containing a malicious attachment, which led to the execution chain of the UAC-0099’s MATCHWOK backdoor.

Once this initial foothold was established, attackers leveraged it to deploy a previously unseen backdoor we named MythicRatatoskr. What makes MythicRatatoskr so interesting is that its C&C server is hosted within the Yggdrasil network - a decentralized mesh network that implements an experimental routing scheme, where IPv6 communication between nodes is protected end-to-end. The backdoor is unique, and we have not observed it again since this incident.

In this talk, we will cover this incident in detail, provide an in-depth analysis of the MythicRatatoskr backdoor, and explain the inner workings of the Yggdrasil network.


About Peter Strýček

Peter Strýček is a Malware Researcher at ESET who enjoys reverse engineering and analyzing complex threats. He has a particular interest in analyzing malware targeting platforms such as Linux and macOS. He presented his research at the AVAR conference and has also worked on topics including a zero-day vulnerability in WinRAR exploited via weaponized job application archives.