Fake Notepad++ Plugin Used to Deliver MATCHBOIL.V2 Malware
Ukraine's CERT-UA warns of UAC-0099 campaign using malicious Notepad++ plugin. The attack targets Windows systems and follows previous WinRAR exploits.
TL;DR
- Ukraine's CERT-UA identifies new UAC-0099 campaign using fake Notepad++ plugin
- Malicious plugin delivers MATCHBOIL.V2 malware to compromise Windows systems
- Threat actors previously exploited WinRAR vulnerabilities in similar attacks
- Organizations should verify plugin sources and monitor for suspicious UAC behavior
- Security teams urged to update endpoint detection and user awareness protocols
A recent cybersecurity alert from Ukraine's Computer Emergency Response Team (CERT-UA) reveals a sophisticated attack campaign leveraging a counterfeit Notepad++ plugin to infiltrate Windows systems. The threat group behind these activities, identified as UAC-0099 and linked to Russian state-sponsored operations, has a documented history of exploiting software vulnerabilities for initial access.
This latest tactic demonstrates the ongoing evolution of supply chain-style attacks, where attackers abuse trusted software ecosystems to deliver malicious payloads. The fake plugin specifically targets users who regularly interact with text editors, potentially granting attackers broad system access through seemingly benign software extensions.
Attack Vector and Malware Analysis
- Attackers distribute malicious payload disguised as legitimate Notepad++ plugin
- Plugin installs MATCHBOIL.V2 malware designed for persistent system compromise
- Initial infection requires user to manually install the fake plugin extension
- Malware likely enables remote access and additional payload deployment
- Windows User Account Control (UAC) bypass techniques may be employed
Defensive Recommendations
- Verify plugin authenticity through official Notepad++ marketplace only
- Implement strict application whitelisting for plugin installations
- Monitor endpoint behavior for unusual UAC elevation requests
- Deploy updated antivirus signatures targeting MATCHBOIL.V2 variants
- Conduct user training on risks of third-party plugin installations
- Review network logs for connections to known malicious infrastructure
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.