Fake Notepad++ plugin helps UAC-0099 deliver MATCHBOIL.V2

Colleagues, I would like to draw your attention to a cybersecurity development.
CERT-UA reports on a UAC-0099 campaign in which attackers disguise a malicious file as a Notepad++ plugin.
The attack starts with a phishing email and an archive attachment. Once opened, the victim sees a lure, while a DLL chain is downloaded and activated in the background, ultimately delivering MATCHBOIL.V2.
Separately, if launched incorrectly, the component may consume significant RAM and CPU, causing additional damage.
Why it matters: these attacks bypass routine user caution and exploit trust in widely used tools.
I would recommend updating WinRAR, 7-Zip, and Notepad++ to the latest versions.
How do you protect endpoints against such delivery chains?
#cybersecurity #phishing #WindowsSecurity #CERTUA


Latest comments
No comments yet.