🟠 High  |  Source: The Hacker News


A Russia-aligned threat group known as UAC-0099 is distributing malware disguised as a legitimate Notepad++ plugin to compromise Windows systems. The malware, identified as MATCHBOIL.V2, has been flagged by Ukraine’s CERT-UA as part of an ongoing targeted campaign. This is significant because it exploits trust in widely used developer tools to bypass user suspicion and deliver a payload.

Security Architect’s Take: Enforce application allowlisting and restrict plugin/extension installation on managed endpoints, particularly for developer tools such as Notepad++. Review endpoint detection rules to flag unsigned or unverified plugins loading into commonly abused applications, and ensure EDR telemetry covers plugin execution paths on Windows hosts.

Original advisory: Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks