Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

Summary

CERT-UA has identified a new campaign by the Russia-aligned threat cluster UAC-0099, which uses a fake Notepad++ plugin to distribute malware. This campaign is designed to compromise Windows systems, building on previous tactics observed from the group involving WinRAR vulnerabilities.

IFF Assessment

FOE

This article details a new malware distribution campaign by a Russia-aligned threat actor, posing a direct threat to defenders.

Defender Context

Defenders should be vigilant about unexpected plugin installations or updates for commonly used software like Notepad++. Phishing attempts that leverage legitimate-looking software can be highly effective, requiring user education and robust endpoint detection and response (EDR) solutions to identify and block such malicious payloads.

Read Full Story →