Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign

Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign

Posted on July 24, 2026 By CWS

The Computer Emergency Response Team of Ukraine (CERT-UA) has issued an alert about a new cyber threat campaign involving fake Notepad++ plugins. This malicious activity is attributed to the UAC-0099 threat group, believed to be aligned with Russian interests, and employs a sophisticated method to infiltrate Windows systems.

Background of the UAC-0099 Threat Group

UAC-0099, active since mid-2022, is known for exploiting vulnerabilities in popular software like WinRAR. Previously, this group has utilized phishing emails to deploy malware strains such as LONEPAGE, MATCHBOIL, and DRAGSTARE. The current campaign represents an evolution of their tactics and continues to target users through deceptive means.

The Mechanics of the New Attack

The latest attack wave commenced with phishing emails containing image attachments. Clicking the image leads to a shortened URL, redirecting victims to a file-sharing site like EasySend[.]co. Here, a ZIP archive is downloaded, which includes a VBScript disguised as a PDF. This script further downloads a decoy PDF and an archive titled ‘Evernote.zip’, which contains several critical components.

Among these components are a genuine version of Notepad++ (8.8.3), a malicious DLL plugin (‘NppExport.dll’), a password-protected archive (‘updater.rar’), and a legitimate WinRAR executable. The VBScript’s objective is to launch Notepad++, which subsequently loads the DLL. The DLL, named LUNCHPOKE, then unpacks additional malicious files, setting up a scheduled task to perpetuate the attack.

Impact and Recommendations

The executable ‘RemoteLibUpdater.exe’, identified as BURNYBEAR, acts as a loader for ‘InitTest.dll’, a variant of MATCHBOIL now dubbed MATCHBOIL.V2. This new version can deliver further payloads, increasing the threat’s complexity. If improperly executed, it can also strain system resources, impacting performance.

To mitigate risks, CERT-UA advises organizations to update their WinRAR, 7-Zip, and Notepad++ software to the latest versions, reducing the potential for exploitation. The alert coincides with reports of a phishing campaign by a Russia-linked threat actor targeting Zimbra mail servers, further underscoring the persistent threat of cyber espionage.

Ongoing Threats and Future Outlook

The U.S. government has spotlighted a related campaign by the group known as Laundry Bear, employing innovative phishing techniques to compromise webmail services. This activity indicates a broader espionage strategy, focusing heavily on Ukrainian and Western targets.

Security firm Proofpoint has also reported continued threats from Russian actors, leveraging cross-site scripting exploits in a campaign named Operation RoundPress. These ongoing cyber threats emphasize the importance of robust security measures and remaining vigilant against evolving tactics.

As cyber threat actors persist in developing new methods of attack, staying informed and ensuring security updates are applied promptly will be critical in defending against these sophisticated campaigns.

The Hacker News Tags:CERT-UA, cyber threat, Cybersecurity, Espionage, Malware, Notepad, Phishing, Russia, software update, UAC-0099

Post navigation

Previous Post: RubyGems Packages Exploit Developer Machines for Monero Mining
Next Post: Microsoft 365 Outage Disrupts Key Business Services

Related Posts

PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces The Hacker News
Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure The Hacker News
npm Enhances Security with 2FA and Install Controls npm Enhances Security with 2FA and Install Controls The Hacker News
UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud The Hacker News
Cross-App Permissions: Unseen Risks and Solutions Cross-App Permissions: Unseen Risks and Solutions The Hacker News
FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Security Flaws in NodeBB Highlight Admin Access Risks
  • Microsoft 365 Outage Disrupts Key Business Services
  • Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign
  • RubyGems Packages Exploit Developer Machines for Monero Mining
  • Origin Energy Confirms Data Breach Impacting Millions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Security Flaws in NodeBB Highlight Admin Access Risks
  • Microsoft 365 Outage Disrupts Key Business Services
  • Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign
  • RubyGems Packages Exploit Developer Machines for Monero Mining
  • Origin Energy Confirms Data Breach Impacting Millions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark