Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Reported exploitedNotepad++UAC-0099WinRAROur summary
A new cyberattack campaign attributed to the Russia-aligned threat group UAC-0099 has been discovered, involving a malicious Notepad++ plugin used to distribute the MATCHBOIL.V2 malware. The attack starts with phishing emails that lead victims to download a ZIP file disguised as a PDF document. This package includes a legitimate copy of Notepad++ version 8.8.3 and a malicious DLL named NppExport.dll. When executed, the script extracts additional components including a modified version of MATCHBOIL, which can deliver further payloads. CERT-UA advises updating Notepad++, WinRAR, and 7-Zip to mitigate risks.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.