hacker-news · Crawled Jul 24, 2026

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

5 IoCs 1 Actors 3 CVEs
Read original article ↗

AI Summary

A Russia-aligned threat cluster known as UAC-0099 is distributing a malicious Notepad++ plugin to deliver MATCHBOIL.V2 malware, a modified version of the C#-based loader MATCHBOIL. The attack begins with a phishing email containing an image that leads to a shortened URL, which redirects to a file-sharing service hosting a malicious ZIP file. The ZIP contains a VBScript that executes a decoy PDF while silently deploying a malicious DLL and additional payloads, including RemoteLibUpdater.exe (BURNYBEAR) and InitTest.dll. The campaign aims to establish persistence and conduct espionage, with no financial motive observed.

AI-extracted · verify before operational use

Extracted Entities 4 found

Indicators of Compromise 5 extracted

Type Value Detail
Domain easysend[.]co Details →
Filename NppExport.dll Details →
Filename RemoteLibUpdater.exe Details →
Filename InitTest.dll Details →
Filename updater.rar Details →

MITRE ATT&CK TTPs 36 techniques

T1053.005 Scheduled Task · Execution T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1204.002 Malicious File · Execution T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1059.003 Windows Command Shell · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1074.001 Local Data Staging · Collection T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1132.002 Non-Standard Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1530 Data from Cloud Storage · Collection T1539 Steal Web Session Cookie · Credential Access T1552 Unsecured Credentials · Credential Access T1557 Adversary-in-the-Middle · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1085 T1085 T1087.002 Domain Account · Discovery T1134 Access Token Manipulation · Defense Evasion T1218 System Binary Proxy Execution · Defense Evasion T1480 Execution Guardrails · Defense Evasion