ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Fake Notepad++ plugin drops MATCHBOIL.V2 in UAC-0099 Windows intrusions

Source headline: Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 17 hours ago

Intelligence Summary

CERT-UA warns about a Windows compromise campaign using a trojanized Notepad++ plugin. Victims are lured to install the fake plugin, which then delivers MATCHBOIL.V2. The activity is attributed to the Russia-aligned UAC-0099 threat cluster. This matters because it blends into a legitimate development/admin workflow, helping initial access and persistence. Organizations using Notepad++ or distributing plugins should review plugin sources and block unexpected binaries.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#supply-chain #malware #windows #matchboil-v2 #notepad #uac-0099
Original reporting The Hacker News Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Open original source