CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

July 24, 2026

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++ plugin to compromise Windows systems. The activity is attributed to the Russia-aligned threat cluster UAC-0099, which has previously exploited WinRAR flaws to deliver LONEPAGE malware and used phishing emails to deploy MATCHBOIL, MATCHWOK, and DRAGSTARE. Active since mid-2022, the latest attacks observed earlier this summer begin with a phishing email containing an image attachment. Clicking the image opens a URL via a link shortener, leading to a file-sharing service like EasySend.co to retrieve a ZIP archive. The ZIP contains a VBScript masquerading as a PDF. Launching it displays a decoy PDF while silently downloading a second archive named ‘Evernote.zip.’ This archive includes a legitimate copy of Notepad++ version 8.8.3, a malicious DLL plugin (NppExport.dll) codenamed LUNCHPOKE, a password-protected archive (updater.rar), and a legitimate WinRAR executable. The VBScript extracts the archive and launches Notepad++, which loads NppExport.dll. LUNCHPOKE unpacks updater.rar containing RemoteLibUpdater.exe and InitTest.dll, sets up persistence via a scheduled task running every three minutes. RemoteLibUpdater.exe is BURNYBEAR, a loader for InitTest.dll, a modified version of MATCHBOIL, a C#-based loader delivering secondary payloads, now codenamed MATCHBOIL.V2. If launched without arguments, BURNYBEAR exhausts computer resources. CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to latest versions. The disclosure also highlights a U.S. government report on Laundry Bear (CL-STA-1114, TA488, Void Blizzard) targeting Zimbra mail servers with a half-click exploit (CVE-2025-66376) delivering ZimReaper JavaScript. Additionally, Proofpoint reported on TA458’s Operation RoundPress using half-click XSS exploits against webmail platforms including Zimbra, Kerio, SOGo, mDaemon, and Roundcube, with zero-day exploits in Kerio and SOGo (CVE-2026-8496). TA458 likely operates as a Russian military intelligence operation, targeting Ukrainian government and Eastern European entities.

CVEs: CVE-2025-66376, CVE-2026-8496, CVE-2025-49113

Attack groups: UAC-0099, Laundry Bear, CL-STA-1114, TA488, Void Blizzard, TA458, APT28

Malware: MATCHBOIL.V2, LONEPAGE, MATCHBOIL, MATCHWOK, DRAGSTARE, BURNYBEAR, LUNCHPOKE, ZimReaper, SpyPress

Companies: CERT-UA, Proofpoint, ESET, Hunt.io

Products: Notepad++, WinRAR, 7-Zip, Zimbra, Kerio Webmail, SOGo Webmail, mDaemon, Roundcube

Service providers: EasySend.co