Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign

Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign

Posted on July 24, 2026 By CWS

The Computer Emergency Response Team of Ukraine (CERT-UA) has issued an alert about a new cyber threat campaign involving fake Notepad++ plugins. This malicious activity is attributed to the UAC-0099 threat group, believed to be aligned with Russian interests, and employs a sophisticated method to infiltrate Windows systems.

Background of the UAC-0099 Threat Group

UAC-0099, active since mid-2022, is known for exploiting vulnerabilities in popular software like WinRAR. Previously, this group has utilized phishing emails to deploy malware strains such as LONEPAGE, MATCHBOIL, and DRAGSTARE. The current campaign represents an evolution of their tactics and continues to target users through deceptive means.

The Mechanics of the New Attack

The latest attack wave commenced with phishing emails containing image attachments. Clicking the image leads to a shortened URL, redirecting victims to a file-sharing site like EasySend[.]co. Here, a ZIP archive is downloaded, which includes a VBScript disguised as a PDF. This script further downloads a decoy PDF and an archive titled ‘Evernote.zip’, which contains several critical components.

Among these components are a genuine version of Notepad++ (8.8.3), a malicious DLL plugin (‘NppExport.dll’), a password-protected archive (‘updater.rar’), and a legitimate WinRAR executable. The VBScript’s objective is to launch Notepad++, which subsequently loads the DLL. The DLL, named LUNCHPOKE, then unpacks additional malicious files, setting up a scheduled task to perpetuate the attack.

Impact and Recommendations

The executable ‘RemoteLibUpdater.exe’, identified as BURNYBEAR, acts as a loader for ‘InitTest.dll’, a variant of MATCHBOIL now dubbed MATCHBOIL.V2. This new version can deliver further payloads, increasing the threat’s complexity. If improperly executed, it can also strain system resources, impacting performance.

To mitigate risks, CERT-UA advises organizations to update their WinRAR, 7-Zip, and Notepad++ software to the latest versions, reducing the potential for exploitation. The alert coincides with reports of a phishing campaign by a Russia-linked threat actor targeting Zimbra mail servers, further underscoring the persistent threat of cyber espionage.

Ongoing Threats and Future Outlook

The U.S. government has spotlighted a related campaign by the group known as Laundry Bear, employing innovative phishing techniques to compromise webmail services. This activity indicates a broader espionage strategy, focusing heavily on Ukrainian and Western targets.

Security firm Proofpoint has also reported continued threats from Russian actors, leveraging cross-site scripting exploits in a campaign named Operation RoundPress. These ongoing cyber threats emphasize the importance of robust security measures and remaining vigilant against evolving tactics.

As cyber threat actors persist in developing new methods of attack, staying informed and ensuring security updates are applied promptly will be critical in defending against these sophisticated campaigns.

The Hacker News Tags:CERT-UA, cyber threat, Cybersecurity, Espionage, Malware, Notepad, Phishing, Russia, software update, UAC-0099

Post navigation

Previous Post: RubyGems Packages Exploit Developer Machines for Monero Mining
Next Post: Microsoft 365 Outage Disrupts Key Business Services

Related Posts

Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution The Hacker News
North Korean Hackers Exploit AI for Enhanced Cyber Attacks North Korean Hackers Exploit AI for Enhanced Cyber Attacks The Hacker News
A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces The Hacker News
Cross-Platform QuimaRAT MaaS Targets Multiple OS Cross-Platform QuimaRAT MaaS Targets Multiple OS The Hacker News
German Agencies Issue Alert on Signal Phishing Threat German Agencies Issue Alert on Signal Phishing Threat The Hacker News
Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenVPN Enhances Security with Critical Update
  • Telerik Vulnerability Chain Allows Remote Code Execution
  • Urgent N-able Hotfix Addresses Critical Security Flaw
  • OpenAI Develops Framework for AI Misalignment Disclosure
  • Russian Hackers Exploit HOOKEDGE Backdoor in Europe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenVPN Enhances Security with Critical Update
  • Telerik Vulnerability Chain Allows Remote Code Execution
  • Urgent N-able Hotfix Addresses Critical Security Flaw
  • OpenAI Develops Framework for AI Misalignment Disclosure
  • Russian Hackers Exploit HOOKEDGE Backdoor in Europe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark