VMTech
Discuss a project

Fake Notepad++ plugin helps UAC-0099 deliver MATCHBOIL.V2

Fake Notepad++ plugin helps UAC-0099 deliver MATCHBOIL.V2

Colleagues, I would like to draw your attention to a cybersecurity development.

CERT-UA reports on a UAC-0099 campaign in which attackers disguise a malicious file as a Notepad++ plugin.

The attack starts with a phishing email and an archive attachment. Once opened, the victim sees a lure, while a DLL chain is downloaded and activated in the background, ultimately delivering MATCHBOIL.V2.

Separately, if launched incorrectly, the component may consume significant RAM and CPU, causing additional damage.

Why it matters: these attacks bypass routine user caution and exploit trust in widely used tools.

I would recommend updating WinRAR, 7-Zip, and Notepad++ to the latest versions.

How do you protect endpoints against such delivery chains?
#cybersecurity #phishing #WindowsSecurity #CERTUA

Open analytics
On the site 12 views
min read 1 24.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Fake Notepad++ plugin helps UAC-0099 deliver MATCHBOIL.V2

Open the post on Instagram ↗