All incidents

Ukraine targeted by fake Notepad++ plugin phishing campaign (UAC-0099)

malwareopenJul 24, 2026 — Jul 24, 2026
Ukraine Hit by Fake Notepad++ Plugin in UAC-0099 Phishing Attack

UKRAINIAN organisations have been hit by a phishing campaign that uses a fake Notepad++ plugin to deliver malware, according to an advisory from CERT-UA. The operation, tracked as UAC‑0099, began on 24 July 2026 and continues to target government and defence entities. The attack chain relies on social engineering rather than a software vulnerability, with no CVE assigned to the activity. The goal is to install a loader that can run further payloads, including a modified version known as MATCHBOIL.V2.

The phishing email contains a link that appears as an image but actually points to a ZIP archive. Inside the archive sits a VBScript file that is made to look like a PDF document, tricking the user into executing it with Windows Script Host. Once run, the script contacts a remote server and downloads a dynamic link library named LUNCHPOKE. This DLL acts as a dropper that installs another loader called BURNYBEAR, which in turn can fetch and execute additional payloads such as the MATCHBOIL.V2 variant. No traditional software flaw is exploited; the infection depends entirely on the user opening the malicious script.

LUNCHPOKE is not signed with a valid certificate and is designed to evade basic antivirus heuristics by using benign‑looking names and packing techniques. BURNYBEAR maintains persistence by creating a scheduled task or registry run key, allowing it to survive reboots. When activated, it pulls down MATCHBOIL.V2, a modified loader that includes extra obfuscation layers and communicates over HTTPS to command‑and‑control servers controlled by UAC‑0099. The campaign does not rely on any known vulnerability, so patching alone will not stop it; user awareness is critical.

UAC‑0099 has been linked to Russian‑aligned cyber espionage efforts since at least 2023, with a history of targeting Ukrainian state bodies, energy companies and media outlets. The fake Notepad++ plugin tactic marks an evolution in their social engineering playbook, moving from macro‑laden documents to trojanised software addons. Security researchers note that the group frequently rotates infrastructure, making IP‑based blocking ineffective. The use of a trusted application’s plugin ecosystem highlights the need for strict controls on third‑party extensions.

Defensive measures should treat any unsolicited email that contains links or attachments with caution, verifying the sender through an independent channel before clicking. Users must be advised to install Notepad++ plugins only from the official repository or trusted sources, and to check digital signatures where available. Administrators can disable Windows Script Host or restrict VBScript execution via Group Policy, reducing the chance that a malicious script runs.

Application control solutions should be configured to allow only known good DLLs, blocking files such as LUNCHPOKE and BURNYBEAR from executing. Email gateways ought to reject ZIP archives that contain executable content, and endpoint protection should be kept up‑to‑date with signatures for the identified malware families. Regular phishing simulations and clear reporting paths to CERT‑UA will help reduce the likelihood of successful infection.

Intelligence briefing updated Jul 24, 2026

UAC-0099
Root sourcecert.gov.ua
Timeline Coverage

Swipe to explore timeline