Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
ID: 17bc8de1-88c0-56e6-8d40-ff26b6819840
STIX ID: report--17bc8de1-88c0-56e6-8d40-ff26b6819840
Feed Name: The Hacker News
CERT-UA warns of a multi-stage phishing campaign by a Russia-aligned cluster (UAC-0099) that delivers a malicious Notepad++ plugin (LUNCHPOKE) which unpacks a RAR containing a loader (BURNYBEAR) and MATCHBOIL.V2, sets persistence via scheduled tasks, and can exhaust system resources if mis-invoked; organizations are advised to update WinRAR, 7-Zip, and Notepad++. The report also highlights Laundry Bear/TA458’s "half-click" webmail exploit (CVE-2025-66376) delivering ZimReaper and SpyPress variants to harvest email and maintain covert long-term access across multiple webmail platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
