AUTO-UPDATED

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine has identified a new cyberattack campaign where Russia-aligned group UAC-0099 uses malicious Notepad++ plugins to compromise Windows systems via phishing emails.

Key Points

  • The UAC-0099 threat group distributes a malicious DLL, codenamed LUNCHPOKE, disguised as a legitimate Notepad++ plugin to execute secondary payloads.
  • Attacks begin with phishing emails containing image attachments that lead victims to download a ZIP archive from file-sharing services like EasySend.
  • The malware chain includes the BURNYBEAR loader and a C#-based tool called MATCHBOIL.V2, which can exhaust system resources if launched incorrectly.
  • CERT-UA advises organizations to update WinRAR, 7-Zip, and Notepad++ to the latest versions to mitigate risks from these exploitation techniques.
  • Separate campaigns by Russian actors, including Laundry Bear and TA458, are currently targeting global webmail servers using "half-click" exploits and zero-day vulnerabilities.

Why it Matters

These campaigns demonstrate an increasing trend of Russian-aligned threat actors using Ukrainian organizations as a testing ground for sophisticated cyber espionage techniques before deploying them globally. The shift toward "half-click" exploits and modular malware highlights a growing risk to both government and commercial entities relying on standard webmail and productivity software.
Internet Published by info@thehackernews.com (The Hacker News)
Read original