UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine
Campaign
Summary
Hide ▲
Show ▼
The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in Ukraine. The chain uses Evernote.zip with a legitimate Notepad++ 8.8.3 copy and NppExport.dll, then unpacks loaders such as BurnyBear and MatchBoil V2. The activity is tied to a cluster previously linked to initial access for APT44 / Sandworm, and it does not rely on a software exploit or supply-chain compromise.
Related Happenings
CERT-UA update advice for Notepad++, 7-Zip, and WinRAR
Advisory/Mitigation
H score15
First: 23.07.2026 19:32
Last: 23.07.2026 19:32
Sources 1
How related:
CERT-UA advises system administrators to update Notepad++ to version 8.9.7, 7-Zip to version 26.02, and WinRAR to version 7.23, to prevent hackers from exploiting known flaws in existing products and enabling stealthy attacks.
About this happening:
CERT-UA told administrators to update Notepad++, 7-Zip, and WinRAR after attackers abused the software in a stealthy delivery chain. The guidance targets known f...
CERT-UA update advice for Notepad++, 7-Zip, and WinRAR
Advisory/MitigationHow related: CERT-UA advises system administrators to update Notepad++ to version 8.9.7, 7-Zip to version 26.02, and WinRAR to version 7.23, to prevent hackers from exploiting known flaws in existing products and enabling stealthy attacks.
About this happening: CERT-UA told administrators to update Notepad++, 7-Zip, and WinRAR after attackers abused the software in a stealthy delivery chain. The guidance targets known f...
AgingFly malware attacks local governments and hospitals in Ukraine
Malware Activity
H score28
First: 16.04.2026 00:57
Last: 16.04.2026 00:57
Sources 1
About this happening:
The AgingFly malware is now being deployed against local governments and hospitals in Ukraine, where it steals browser and WhatsApp authentication data and enables dee...
AgingFly malware attacks local governments and hospitals in Ukraine
Malware ActivityAbout this happening: The AgingFly malware is now being deployed against local governments and hospitals in Ukraine, where it steals browser and WhatsApp authentication data and enables dee...
Timeline
-
23.07.2026 19:32 2 articles · 1h ago
CERT-UA uncovers UAC-0099 Notepad++ plugin delivery campaign
Initial DisclosureCERT-UA says UAC-0099 is distributing ZIP/VBS lures that masquerade as a PDF, install a legitimate Notepad++ 8.8.3 copy, and sideload malicious NppExport.dll as LunchPoke to create persistence and stage BurnyBear and MatchBoil V2. The advisory ties the activity to organizations in Ukraine, says the attackers do not exploit a software vulnerability or supply-chain compromise, and recommends updating Notepad++ to 8.9.7, 7-Zip to 26.02, and WinRAR to 7.23.
Show sources
- Hackers abuse Notepad++ plugins to stealthily install malware — www.bleepingcomputer.com — 23.07.2026 19:32
- Hackers abuse Notepad++ plugins to stealthily install malware — www.bleepingcomputer.com — 23.07.2026 19:32