Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
A Russia-aligned threat group, UAC-0099, is using a malicious Notepad++ plugin to compromise Windows systems, delivering the MATCHBOIL.V2 malware via sophisticated phishing campaigns.
Intelligence analysis by Gemini 2.5 Flash

The attacks begin with phishing emails containing image attachments that lead to a VBScript disguised as a PDF. This script downloads a decoy PDF while silently installing a legitimate Notepad++ version bundled with a malicious DLL plugin, 'NppExport.dll,' which then unpacks and executes the MATCHBOIL.V2 loader, establishing persistence.
Imagine someone sends you a fake toy that looks like a popular building block set. When you try to play with it, it secretly installs a tiny spy robot on your computer that can steal your secrets. This spy robot can also make your computer really slow if it's not set up just right. Bad guys from a certain country are using this trick to sneak into computers and steal information, especially from important organizations.
Analysis
The Deceptive Notepad++ Campaign
The Computer Emergency Response Team of Ukraine (CERT-UA) has detailed a new campaign attributed to the Russia-aligned threat cluster UAC-0099, which leverages a highly deceptive method to compromise Windows systems. The attack chain initiates with a phishing email containing an image attachment. When clicked, this image redirects the victim through a link shortener to a file-sharing service, from which a ZIP archive is retrieved. This archive contains a Visual Basic Script (VBScript) masquerading as a PDF document, designed to execute a multi-stage infection process.
Upon execution, the VBScript downloads and displays a decoy PDF to distract the user, while simultaneously downloading a second archive named "Evernote.zip." This second archive is crucial, as it contains a legitimate Notepad++ editor, a malicious DLL plugin named "NppExport.dll" (codenamed LUNCHPOKE), a password-protected RAR archive, and a legitimate WinRAR executable. The LUNCHPOKE DLL is engineered to unpack the RAR archive, which holds "RemoteLibUpdater.exe" and "InitTest.dll," into a specific directory. It then establishes persistence by creating a scheduled task to run "RemoteLibUpdater.exe" every three minutes, ensuring continuous access for the attackers.
Evolution of MATCHBOIL and UAC-0099
The "RemoteLibUpdater.exe" binary, identified as BURNYBEAR, acts as a loader for "InitTest.dll," which is a modified version of the C#-based loader known as MATCHBOIL, now designated as MATCHBOIL.V2. This updated version is capable of delivering secondary payloads, indicating a flexible and adaptable malware infrastructure. CERT-UA also noted a defensive mechanism within BURNYBEAR: if launched incorrectly without specified arguments, it activates logic to exhaust computer resources, potentially hindering analysis or system recovery. UAC-0099 has been active since at least mid-2022, previously weaponizing WinRAR flaws to deploy LONEPAGE and employing phishing for MATCHBOIL, MATCHWOK, and DRAGSTARE delivery. CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to mitigate such threats.
Broader Russian Cyber Espionage Landscape
This campaign is part of a broader pattern of sophisticated cyber espionage activities linked to Russian threat actors. The U.S. government recently highlighted a phishing campaign by Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) targeting Zimbra mail servers of Western government and commercial organizations since July 2025. This group uses a novel "half-click" exploit (CVE-2025-66376) to deliver malicious JavaScript, ZimReaper, for harvesting sensitive data, requiring only a user to view a malicious email. This covert activity, lacking financial extortion, strongly suggests Russian government-backed espionage, often testing techniques on Ukrainian targets before wider deployment.
Furthermore, Proofpoint reported on Operation RoundPress by TA458, another Russian threat actor, which continues to target webmail services like Zimbra, Kerio, SOGo, mDaemon, and Roundcube using half-click cross-site scripting (XSS) exploits. Since May 2025, TA458 has evolved its SpyPress malware, removing stealing components and integrating interactive backdoor mechanisms for long-term access, exploiting vulnerabilities like CVE-2025-49113 in Roundcube. TA458, believed to be a Russian military intelligence operation distinct from APT28, primarily targets Ukrainian, Eastern European military, and government entities, underscoring the persistent and multi-faceted nature of Russian state-sponsored cyber threats.
Key points
- UAC-0099, a Russia-aligned group, is deploying MATCHBOIL.V2 via a malicious Notepad++ plugin.
- The attack chain involves phishing emails, a VBScript disguised as a PDF, and a decoy document.
- The malware establishes persistence through a scheduled task and can exhaust system resources if launched incorrectly.
- CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to the latest versions.
- This campaign aligns with broader Russian cyber espionage efforts, including 'half-click' exploits and webmail targeting by groups like Laundry Bear and TA458.
The disclosure by CERT-UA provides crucial intelligence, enabling organizations to proactively update their software and implement stronger security measures, potentially reducing the success rate of these sophisticated phishing and malware campaigns.
The continuous evolution of state-sponsored threat actors like UAC-0099 and TA458, coupled with their use of novel exploits and deceptive tactics, suggests that organizations will face an ongoing and escalating challenge in defending against persistent cyber espionage.



