UAC-0099 fake Notepad++ plugin campaign
Campaign
Summary
Hide ▲
Show ▼
A UAC-0099 phishing campaign is using a fake Notepad++ plugin chain to compromise Windows systems and deploy MATCHBOIL.V2 with scheduled-task persistence. The lure starts with a phishing email and an image attachment, then pivots through a shortened URL to EasySend[.]co and a ZIP archive. The payload chain hides a VBScript as a PDF, stages Evernote.zip, and loads a malicious NppExport.dll plugin to unpack the next components. The operation expands the group’s Windows intrusion toolkit and increases the risk of follow-on payload delivery and long-term access.
Related Happenings
UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine
Campaign
H score33
First: 23.07.2026 19:32
Last: 23.07.2026 19:32
Sources 1
About this happening:
The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in...
UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine
CampaignAbout this happening: The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
Campaign
H score24
First: 19.07.2026 16:30
Last: 19.07.2026 16:30
Sources 1
About this happening:
A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at l...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
CampaignAbout this happening: A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at l...
SHADOW#REACTOR fake .ttf phishing campaign targeting Windows systems
Campaign
H score31
First: 16.07.2026 18:00
Last: 16.07.2026 18:00
Sources 1
About this happening:
A large-scale phishing campaign is delivering RATs and infostealers to Windows systems by disguising a malicious script as a .ttf font file. The operation has...
SHADOW#REACTOR fake .ttf phishing campaign targeting Windows systems
CampaignAbout this happening: A large-scale phishing campaign is delivering RATs and infostealers to Windows systems by disguising a malicious script as a .ttf font file. The operation has...
BadPaw multi-stage backdoor deployment targeting Ukraine
Malware Activity
H score22
First: 04.03.2026 16:30
Last: 04.03.2026 16:30
Sources 1
About this happening:
Researchers uncovered BadPaw, a multi-stage malware operation that uses ukr[.]net-hosted email lures and staged redirects to install a backdoor on Ukrainian target...
BadPaw multi-stage backdoor deployment targeting Ukraine
Malware ActivityAbout this happening: Researchers uncovered BadPaw, a multi-stage malware operation that uses ukr[.]net-hosted email lures and staged redirects to install a backdoor on Ukrainian target...
APT36 / SideCopy phishing-led campaign targeting Indian defense organizations
Campaign
H score38
First: 11.02.2026 16:52
Last: 11.02.2026 16:52
Sources 1
About this happening:
A phishing-led APT36 / SideCopy campaign is targeting Indian defense and government-aligned organizations, using cross-platform RATs to steal sensitive data and ke...
APT36 / SideCopy phishing-led campaign targeting Indian defense organizations
CampaignAbout this happening: A phishing-led APT36 / SideCopy campaign is targeting Indian defense and government-aligned organizations, using cross-platform RATs to steal sensitive data and ke...
Timeline
-
24.07.2026 09:50 2 articles · 12h ago
CERT-UA warns of a fake Notepad++ plugin campaign against Windows systems
Initial DisclosureCERT-UA says UAC-0099 is using a malicious program disguised as a Notepad++ plugin to compromise Windows systems. The campaign was observed earlier this summer and starts with a phishing email containing an image attachment, then pivots through a shortened URL to EasySend[.]co to retrieve a ZIP archive; the chain uses a VBScript masquerading as a PDF to stage a second archive, load NppExport.dll (LUNCHPOKE), unpack RemoteLibUpdater.exe and InitTest.dll, and establish persistence with a scheduled task that runs RemoteLibUpdater.exe every three minutes. CERT-UA also said BURNYBEAR can exhaust RAM and processor if RemoteLibUpdater.exe is launched without arguments.
Show sources
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks — thehackernews.com — 24.07.2026 09:50
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks — thehackernews.com — 24.07.2026 09:50