Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, loader, supply-chain, cybercrime-group] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

CERT-UA warned of a Russia-aligned threat cluster (UAC-0099) using a malicious Notepad++ plugin to compromise Windows systems. The campaign begins with phishing emails containing image attachments that lead to a ZIP archive via file-sharing services.

Overview

Attribute Detail
Date 2026-07-24
Threat Actor UAC-0099 (Russia-aligned)
Target Windows systems
Malware MATCHBOIL.V2
Initial Access Phishing โ†’ image attachment โ†’ file-sharing link โ†’ ZIP archive
Lure Fake Notepad++ plugin

Attack Chain

  1. Victims receive phishing emails with image attachments
  2. Images contain links to file-sharing services hosting ZIP archives
  3. ZIP contains a malicious Notepad++ plugin
  4. Plugin delivers MATCHBOIL.V2 malware
  5. Full Windows system compromise

Significance

This attack targets users of the popular Notepad++ text editor by weaponising its plugin ecosystem. The use of legitimate file-sharing services for malware distribution makes detection more difficult. UAC-0099's alignment with Russian strategic interests suggests espionage or disruptive intent against Ukrainian and potentially Western targets.

Related Pages