discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

A Russia-aligned threat group, UAC-0099, is using a malicious Notepad++ plugin to compromise Windows systems, delivering the MATCHBOIL.V2 malware via sophisticated phishing campaigns.

By Ravie Lakshmanan·Jul 24·thehackernews.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Image: thehackernews.com

The attacks begin with phishing emails containing image attachments that lead to a VBScript disguised as a PDF. This script downloads a decoy PDF while silently installing a legitimate Notepad++ version bundled with a malicious DLL plugin, 'NppExport.dll,' which then unpacks and executes the MATCHBOIL.V2 loader, establishing persistence.

Why it matters

This story highlights the evolving sophistication of state-sponsored cyber espionage, demonstrating new methods for initial access and persistence, and underscoring the critical need for vigilance against seemingly benign software components and advanced phishing tactics.

Imagine someone sends you a fake toy that looks like a popular building block set. When you try to play with it, it secretly installs a tiny spy robot on your computer that can steal your secrets. This spy robot can also make your computer really slow if it's not set up just right. Bad guys from a certain country are using this trick to sneak into computers and steal information, especially from important organizations.

Analysis

The Deceptive Notepad++ Campaign

The Computer Emergency Response Team of Ukraine (CERT-UA) has detailed a new campaign attributed to the Russia-aligned threat cluster UAC-0099, which leverages a highly deceptive method to compromise Windows systems. The attack chain initiates with a phishing email containing an image attachment. When clicked, this image redirects the victim through a link shortener to a file-sharing service, from which a ZIP archive is retrieved. This archive contains a Visual Basic Script (VBScript) masquerading as a PDF document, designed to execute a multi-stage infection process.

Upon execution, the VBScript downloads and displays a decoy PDF to distract the user, while simultaneously downloading a second archive named "Evernote.zip." This second archive is crucial, as it contains a legitimate Notepad++ editor, a malicious DLL plugin named "NppExport.dll" (codenamed LUNCHPOKE), a password-protected RAR archive, and a legitimate WinRAR executable. The LUNCHPOKE DLL is engineered to unpack the RAR archive, which holds "RemoteLibUpdater.exe" and "InitTest.dll," into a specific directory. It then establishes persistence by creating a scheduled task to run "RemoteLibUpdater.exe" every three minutes, ensuring continuous access for the attackers.

Evolution of MATCHBOIL and UAC-0099

The "RemoteLibUpdater.exe" binary, identified as BURNYBEAR, acts as a loader for "InitTest.dll," which is a modified version of the C#-based loader known as MATCHBOIL, now designated as MATCHBOIL.V2. This updated version is capable of delivering secondary payloads, indicating a flexible and adaptable malware infrastructure. CERT-UA also noted a defensive mechanism within BURNYBEAR: if launched incorrectly without specified arguments, it activates logic to exhaust computer resources, potentially hindering analysis or system recovery. UAC-0099 has been active since at least mid-2022, previously weaponizing WinRAR flaws to deploy LONEPAGE and employing phishing for MATCHBOIL, MATCHWOK, and DRAGSTARE delivery. CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to mitigate such threats.

Broader Russian Cyber Espionage Landscape

This campaign is part of a broader pattern of sophisticated cyber espionage activities linked to Russian threat actors. The U.S. government recently highlighted a phishing campaign by Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) targeting Zimbra mail servers of Western government and commercial organizations since July 2025. This group uses a novel "half-click" exploit (CVE-2025-66376) to deliver malicious JavaScript, ZimReaper, for harvesting sensitive data, requiring only a user to view a malicious email. This covert activity, lacking financial extortion, strongly suggests Russian government-backed espionage, often testing techniques on Ukrainian targets before wider deployment.

Furthermore, Proofpoint reported on Operation RoundPress by TA458, another Russian threat actor, which continues to target webmail services like Zimbra, Kerio, SOGo, mDaemon, and Roundcube using half-click cross-site scripting (XSS) exploits. Since May 2025, TA458 has evolved its SpyPress malware, removing stealing components and integrating interactive backdoor mechanisms for long-term access, exploiting vulnerabilities like CVE-2025-49113 in Roundcube. TA458, believed to be a Russian military intelligence operation distinct from APT28, primarily targets Ukrainian, Eastern European military, and government entities, underscoring the persistent and multi-faceted nature of Russian state-sponsored cyber threats.

Key points

  • UAC-0099, a Russia-aligned group, is deploying MATCHBOIL.V2 via a malicious Notepad++ plugin.
  • The attack chain involves phishing emails, a VBScript disguised as a PDF, and a decoy document.
  • The malware establishes persistence through a scheduled task and can exhaust system resources if launched incorrectly.
  • CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to the latest versions.
  • This campaign aligns with broader Russian cyber espionage efforts, including 'half-click' exploits and webmail targeting by groups like Laundry Bear and TA458.
The Upside

The disclosure by CERT-UA provides crucial intelligence, enabling organizations to proactively update their software and implement stronger security measures, potentially reducing the success rate of these sophisticated phishing and malware campaigns.

The Downside

The continuous evolution of state-sponsored threat actors like UAC-0099 and TA458, coupled with their use of novel exploits and deceptive tactics, suggests that organizations will face an ongoing and escalating challenge in defending against persistent cyber espionage.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycyber-espionagemalwarephishingrussiaukrainewindowsopen-source

Author

Ravie Lakshmanan

Intelligence analysis by

Gemini 2.5 Flash

Published

Jul 24, 2026

Source

thehackernews.com

Share

Topics

securitycyber-espionagemalwarephishingrussiaukrainewindowsopen-source

Related

More from this desk

Jul 23·bleepingcomputer.com

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan uses an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.

Jul 23·bleepingcomputer.com

Australian energy provider Origin says data breach exposes client data

Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). The company has 4.8 million customers and is currently investigating how many of them have been impacted to i…

Jul 23·bleepingcomputer.com

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A Bing malvertising campaign pushed a fake Claude desktop app that delivered SectopRAT malware, compromising at least 29 organizations in two days. The lure abused a legitimate Anthropic Claude.ai Artifact as its landing page.

Jul 23·thehackernews.com

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal mail and 2FA codes. The group targeted Western government and commercial organizations through Zimbra since at least July 2025.