Exploited in the wild Notepad++ UAC-0099 malware WinRAR phishing
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
CVE Tools coverage
A new cyberattack campaign attributed to the Russia-aligned threat group UAC-0099 has been discovered, involving a malicious Notepad++ plugin used to distribute the MATCHBOIL.V2 malware. The attack starts with phishing emails that lead victims to download a ZIP file disguised as a PDF document. This package includes a legitimate copy of Notepad++ version 8.8.3 and a malicious DLL named NppExport.dll. When executed, the script extracts additional components including a modified version of MATCHBOIL, which can deliver further payloads. CERT-UA advises updating Notepad++, WinRAR, and 7-Zip to mitigate risks.