logo

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

ID: 17bc8de1-88c0-56e6-8d40-ff26b6819840

STIX ID: report--17bc8de1-88c0-56e6-8d40-ff26b6819840

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: [email protected] (The Hacker News)

...
...

CERT-UA warns of a multi-stage phishing campaign by a Russia-aligned cluster (UAC-0099) that delivers a malicious Notepad++ plugin (LUNCHPOKE) which unpacks a RAR containing a loader (BURNYBEAR) and MATCHBOIL.V2, sets persistence via scheduled tasks, and can exhaust system resources if mis-invoked; organizations are advised to update WinRAR, 7-Zip, and Notepad++. The report also highlights Laundry Bear/TA458’s "half-click" webmail exploit (CVE-2025-66376) delivering ZimReaper and SpyPress variants to harvest email and maintain covert long-term access across multiple webmail platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.