By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Fake Notepad++ Plugin Used in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has issued a warning regarding a new cyberattack campaign that utilizes a malicious program disguised as a Notepad++ plugin. This campaign aims to compromise Windows systems and has been attributed by CERT-UA to a threat cluster known as UAC-0099. This group is aligned with Russia and has a history of exploiting security vulnerabilities, including those found in WinRAR software, for malicious purposes.
The UAC-0099 threat cluster has been observed deploying the MATCHBOIL.V2 malware through this fake Notepad++ plugin. The malware is designed to establish a backdoor on compromised systems, allowing attackers to gain persistent access and potentially exfiltrate sensitive data. CERT-UA's analysis indicates that the attackers are actively targeting Ukrainian entities, though the full scope of their targets may extend beyond this region.
This tactic of disguising malware as legitimate software or plugins is a common social engineering technique used by threat actors to bypass security measures and trick users into installing malicious code. The use of a popular code editor like Notepad++ as a vector highlights the attackers' strategy to exploit trusted software environments. CERT-UA has provided technical details and indicators of compromise to assist organizations in detecting and mitigating these attacks. The agency urges users to remain vigilant and ensure their software is updated and protected by robust security solutions.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.