Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Summary
CERT-UA has identified a new campaign by the Russia-aligned threat cluster UAC-0099, which uses a fake Notepad++ plugin to distribute malware. This campaign is designed to compromise Windows systems, building on previous tactics observed from the group involving WinRAR vulnerabilities.
IFF Assessment
FOE
This article details a new malware distribution campaign by a Russia-aligned threat actor, posing a direct threat to defenders.
Defender Context
Defenders should be vigilant about unexpected plugin installations or updates for commonly used software like Notepad++. Phishing attempts that leverage legitimate-looking software can be highly effective, requiring user education and robust endpoint detection and response (EDR) solutions to identify and block such malicious payloads.