hacker-news · Crawled Jul 24, 2026

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

5 IoCs 1 Actors 3 CVEs
Read original article ↗

AI Summary

A Russia-aligned threat cluster known as UAC-0099 is distributing a malicious Notepad++ plugin to deliver MATCHBOIL.V2 malware, a modified version of the C#-based loader MATCHBOIL. The attack begins with a phishing email containing an image that leads to a shortened URL, which redirects to a file-sharing service hosting a malicious ZIP file. The ZIP contains a VBScript that executes a decoy PDF while silently deploying a malicious DLL and additional payloads, including RemoteLibUpdater.exe (BURNYBEAR) and InitTest.dll. The campaign aims to establish persistence and conduct espionage, with no financial motive observed.

AI-extracted · verify before operational use

Extracted Entities 4 found

Indicators of Compromise 5 extracted

Type Value Detail
Domain easysend[.]co Details →
Filename NppExport.dll Details →
Filename RemoteLibUpdater.exe Details →
Filename InitTest.dll Details →
Filename updater.rar Details →

MITRE ATT&CK TTPs 25 techniques