Find notable cyber news and cases, enriched with sources, timelines, and signals.

UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in Ukraine. The chain uses Evernote.zip with a legitimate Notepad++ 8.8.3 copy and NppExport.dll, then unpacks loaders such as BurnyBear and MatchBoil V2. The activity is tied to a cluster previously linked to initial access for APT44 / Sandworm, and it does not rely on a software exploit or supply-chain compromise.

Related Happenings

CERT-UA update advice for Notepad++, 7-Zip, and WinRAR

Advisory/Mitigation
H score15 First: 23.07.2026 19:32 Last: 23.07.2026 19:32 Sources 1

How related: CERT-UA advises system administrators to update Notepad++ to version 8.9.7, 7-Zip to version 26.02, and WinRAR to version 7.23, to prevent hackers from exploiting known flaws in existing products and enabling stealthy attacks.

About this happening: CERT-UA told administrators to update Notepad++, 7-Zip, and WinRAR after attackers abused the software in a stealthy delivery chain. The guidance targets known f...

AgingFly malware attacks local governments and hospitals in Ukraine

Malware Activity
H score28 First: 16.04.2026 00:57 Last: 16.04.2026 00:57 Sources 1

About this happening: The AgingFly malware is now being deployed against local governments and hospitals in Ukraine, where it steals browser and WhatsApp authentication data and enables dee...

Timeline

  1. 23.07.2026 19:32 2 articles · 1h ago

    CERT-UA uncovers UAC-0099 Notepad++ plugin delivery campaign

    Initial Disclosure

    CERT-UA says UAC-0099 is distributing ZIP/VBS lures that masquerade as a PDF, install a legitimate Notepad++ 8.8.3 copy, and sideload malicious NppExport.dll as LunchPoke to create persistence and stage BurnyBear and MatchBoil V2. The advisory ties the activity to organizations in Ukraine, says the attackers do not exploit a software vulnerability or supply-chain compromise, and recommends updating Notepad++ to 8.9.7, 7-Zip to 26.02, and WinRAR to 7.23.

    Show sources