Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign

Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign

Posted on July 24, 2026 By CWS

The Computer Emergency Response Team of Ukraine (CERT-UA) has issued an alert about a new cyber threat campaign involving fake Notepad++ plugins. This malicious activity is attributed to the UAC-0099 threat group, believed to be aligned with Russian interests, and employs a sophisticated method to infiltrate Windows systems.

Background of the UAC-0099 Threat Group

UAC-0099, active since mid-2022, is known for exploiting vulnerabilities in popular software like WinRAR. Previously, this group has utilized phishing emails to deploy malware strains such as LONEPAGE, MATCHBOIL, and DRAGSTARE. The current campaign represents an evolution of their tactics and continues to target users through deceptive means.

The Mechanics of the New Attack

The latest attack wave commenced with phishing emails containing image attachments. Clicking the image leads to a shortened URL, redirecting victims to a file-sharing site like EasySend[.]co. Here, a ZIP archive is downloaded, which includes a VBScript disguised as a PDF. This script further downloads a decoy PDF and an archive titled ‘Evernote.zip’, which contains several critical components.

Among these components are a genuine version of Notepad++ (8.8.3), a malicious DLL plugin (‘NppExport.dll’), a password-protected archive (‘updater.rar’), and a legitimate WinRAR executable. The VBScript’s objective is to launch Notepad++, which subsequently loads the DLL. The DLL, named LUNCHPOKE, then unpacks additional malicious files, setting up a scheduled task to perpetuate the attack.

Impact and Recommendations

The executable ‘RemoteLibUpdater.exe’, identified as BURNYBEAR, acts as a loader for ‘InitTest.dll’, a variant of MATCHBOIL now dubbed MATCHBOIL.V2. This new version can deliver further payloads, increasing the threat’s complexity. If improperly executed, it can also strain system resources, impacting performance.

To mitigate risks, CERT-UA advises organizations to update their WinRAR, 7-Zip, and Notepad++ software to the latest versions, reducing the potential for exploitation. The alert coincides with reports of a phishing campaign by a Russia-linked threat actor targeting Zimbra mail servers, further underscoring the persistent threat of cyber espionage.

Ongoing Threats and Future Outlook

The U.S. government has spotlighted a related campaign by the group known as Laundry Bear, employing innovative phishing techniques to compromise webmail services. This activity indicates a broader espionage strategy, focusing heavily on Ukrainian and Western targets.

Security firm Proofpoint has also reported continued threats from Russian actors, leveraging cross-site scripting exploits in a campaign named Operation RoundPress. These ongoing cyber threats emphasize the importance of robust security measures and remaining vigilant against evolving tactics.

As cyber threat actors persist in developing new methods of attack, staying informed and ensuring security updates are applied promptly will be critical in defending against these sophisticated campaigns.

The Hacker News Tags:CERT-UA, cyber threat, Cybersecurity, Espionage, Malware, Notepad, Phishing, Russia, software update, UAC-0099

Post navigation

Previous Post: RubyGems Packages Exploit Developer Machines for Monero Mining
Next Post: Microsoft 365 Outage Disrupts Key Business Services

Related Posts

CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms The Hacker News
Ghostwriter Uses Phishing to Target Ukraine with Malware Ghostwriter Uses Phishing to Target Ukraine with Malware The Hacker News
Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices The Hacker News
17,500 Phishing Domains Target 316 Brands Across 74 Countries in Global PhaaS Surge 17,500 Phishing Domains Target 316 Brands Across 74 Countries in Global PhaaS Surge The Hacker News
FBI Warns of Rising ATM Jackpotting Losses Exceeding M FBI Warns of Rising ATM Jackpotting Losses Exceeding $20M The Hacker News
Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft 365 Outage Disrupts Key Business Services
  • Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign
  • RubyGems Packages Exploit Developer Machines for Monero Mining
  • Origin Energy Confirms Data Breach Impacting Millions
  • Decathlon Data Breach Allegations: 160 Million Records at Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft 365 Outage Disrupts Key Business Services
  • Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign
  • RubyGems Packages Exploit Developer Machines for Monero Mining
  • Origin Energy Confirms Data Breach Impacting Millions
  • Decathlon Data Breach Allegations: 160 Million Records at Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark