UAC- 0099, a Russia-aligned threat actor, is targeting Ukrainian organizations by delivering malware through a fraudulent Notepad++ plugin as part of a phishing campaign. The attack begins with a phishing email containing a disguised image link that leads to a ZIP file. Inside, a VBScript file masquerades as a PDF, triggering the download of a malicious DLL and other files.
The malicious DLL, named LUNCHPOKE, installs a loader, BURNYBEAR, which can execute further payloads, including a modified loader known as MATCHBOIL.V2. This campaign underscores the importance of updating software to mitigate vulnerabilities exploited by such threat actors.