Find notable cyber news and cases, enriched with sources, timelines, and signals.

UAC-0099 fake Notepad++ plugin campaign

Campaign
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

A UAC-0099 phishing campaign is using a fake Notepad++ plugin chain to compromise Windows systems and deploy MATCHBOIL.V2 with scheduled-task persistence. The lure starts with a phishing email and an image attachment, then pivots through a shortened URL to EasySend[.]co and a ZIP archive. The payload chain hides a VBScript as a PDF, stages Evernote.zip, and loads a malicious NppExport.dll plugin to unpack the next components. The operation expands the group’s Windows intrusion toolkit and increases the risk of follow-on payload delivery and long-term access.

Related Happenings

UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine

Campaign
H score33 First: 23.07.2026 19:32 Last: 23.07.2026 19:32 Sources 1

About this happening: The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in...

UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets

Campaign
H score24 First: 19.07.2026 16:30 Last: 19.07.2026 16:30 Sources 1

About this happening: A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at l...

SHADOW#REACTOR fake .ttf phishing campaign targeting Windows systems

Campaign
H score31 First: 16.07.2026 18:00 Last: 16.07.2026 18:00 Sources 1

About this happening: A large-scale phishing campaign is delivering RATs and infostealers to Windows systems by disguising a malicious script as a .ttf font file. The operation has...

BadPaw multi-stage backdoor deployment targeting Ukraine

Malware Activity
H score22 First: 04.03.2026 16:30 Last: 04.03.2026 16:30 Sources 1

About this happening: Researchers uncovered BadPaw, a multi-stage malware operation that uses ukr[.]net-hosted email lures and staged redirects to install a backdoor on Ukrainian target...

APT36 / SideCopy phishing-led campaign targeting Indian defense organizations

Campaign
H score38 First: 11.02.2026 16:52 Last: 11.02.2026 16:52 Sources 1

About this happening: A phishing-led APT36 / SideCopy campaign is targeting Indian defense and government-aligned organizations, using cross-platform RATs to steal sensitive data and ke...

Timeline

  1. 24.07.2026 09:50 2 articles · 12h ago

    CERT-UA warns of a fake Notepad++ plugin campaign against Windows systems

    Initial Disclosure

    CERT-UA says UAC-0099 is using a malicious program disguised as a Notepad++ plugin to compromise Windows systems. The campaign was observed earlier this summer and starts with a phishing email containing an image attachment, then pivots through a shortened URL to EasySend[.]co to retrieve a ZIP archive; the chain uses a VBScript masquerading as a PDF to stage a second archive, load NppExport.dll (LUNCHPOKE), unpack RemoteLibUpdater.exe and InitTest.dll, and establish persistence with a scheduled task that runs RemoteLibUpdater.exe every three minutes. CERT-UA also said BURNYBEAR can exhaust RAM and processor if RemoteLibUpdater.exe is launched without arguments.

    Show sources