Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
UAC-0099 is a Russia-aligned threat cluster tracked by CERT-UA, active since at least mid-2022. It has used phishing emails and exploits in…
Russian APT group Gamaredon has continued its cyber onslaught against Ukraine throughout 2025, deploying new malware and increasingly abusing legitimate cloud services.…
RomCom is a Russian hacking group that has exploited CVE-2025-8088, a WinRAR vulnerability, in attacks targeting Ukraine. They are known for cyber…
WinRAR is a file archiver utility that has been exploited by UAC-0099 in previous attacks and used legitimately in the latest campaign…
Google Threat Intelligence Group (GTIG) has attributed a previously undocumented .NET backdoor named STOCKSTAY to the Russian state-sponsored threat actor Turla. The…
A now-patched flaw in WinRAR (CVE-2025-8088) was weaponized by Gamaredon to place malicious HTA downloaders into the Windows Startup folder, enabling automatic…