type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, loader, supply-chain, cybercrime-group] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
CERT-UA warned of a Russia-aligned threat cluster (UAC-0099) using a malicious Notepad++ plugin to compromise Windows systems. The campaign begins with phishing emails containing image attachments that lead to a ZIP archive via file-sharing services.
Overview
| Attribute | Detail |
|---|---|
| Date | 2026-07-24 |
| Threat Actor | UAC-0099 (Russia-aligned) |
| Target | Windows systems |
| Malware | MATCHBOIL.V2 |
| Initial Access | Phishing โ image attachment โ file-sharing link โ ZIP archive |
| Lure | Fake Notepad++ plugin |
Attack Chain
- Victims receive phishing emails with image attachments
- Images contain links to file-sharing services hosting ZIP archives
- ZIP contains a malicious Notepad++ plugin
- Plugin delivers MATCHBOIL.V2 malware
- Full Windows system compromise
Significance
This attack targets users of the popular Notepad++ text editor by weaponising its plugin ecosystem. The use of legitimate file-sharing services for malware distribution makes detection more difficult. UAC-0099's alignment with Russian strategic interests suggests espionage or disruptive intent against Ukrainian and potentially Western targets.
Related Pages
- Golden Chickens Resurfaces With Four New Malware Families โ ClickFix-style delivery by TAG-127/TAG-195