🟠 High | Source: The Hacker News
A Russia-aligned threat group known as UAC-0099 is distributing malware disguised as a legitimate Notepad++ plugin to compromise Windows systems. The malware, identified as MATCHBOIL.V2, has been flagged by Ukraine’s CERT-UA as part of an ongoing targeted campaign. This is significant because it exploits trust in widely used developer tools to bypass user suspicion and deliver a payload.
Security Architect’s Take: Enforce application allowlisting and restrict plugin/extension installation on managed endpoints, particularly for developer tools such as Notepad++. Review endpoint detection rules to flag unsigned or unverified plugins loading into commonly abused applications, and ensure EDR telemetry covers plugin execution paths on Windows hosts.
Original advisory: Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks