securityaffairs.com 7/24/2026, 11:00:44 AM · external

Ukraine Hit by Fake Notepad++ Plugin in UAC-0099 Phishing Attack

Ukraine Hit by Fake Notepad++ Plugin in UAC-0099 Phishing Attack
Developing story malware 2 articles tracked
Ukraine targeted by fake Notepad++ plugin phishing campaign (UAC-0099)
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cert.gov.ua
Threat Actor

UAC- 0099, a Russia-aligned threat actor, is targeting Ukrainian organizations by delivering malware through a fraudulent Notepad++ plugin as part of a phishing campaign. The attack begins with a phishing email containing a disguised image link that leads to a ZIP file. Inside, a VBScript file masquerades as a PDF, triggering the download of a malicious DLL and other files.

The malicious DLL, named LUNCHPOKE, installs a loader, BURNYBEAR, which can execute further payloads, including a modified loader known as MATCHBOIL.V2. This campaign underscores the importance of updating software to mitigate vulnerabilities exploited by such threat actors.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline