Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

CERT-UA has identified a campaign where a fake Notepad++ plugin delivers MATCHBOIL.V2 malware, linked to the Russia-aligned UAC-0099 threat group targeting Windows systems.

Why it matters

This campaign demonstrates the use of software supply chain deception to compromise Windows endpoints, increasing the risk of infiltration by a state-aligned threat actor.

SOC impact

Monitor Windows endpoints for indicators related to MATCHBOIL.V2 and suspicious activity involving Notepad++ plugins. Review telemetry for signs of UAC-0099 tactics and any unusual plugin installations to assess potential exposure.

Recommended actions

  1. Identify Windows systems with deployed Notepad++ plugins
  2. Review logs for unexpected plugin installation activity
  3. Monitor endpoint telemetry for MATCHBOIL.V2 indicators
  4. Investigate anomalies associated with UAC-0099 threat patterns
  5. Confirm integrity of software supply chain components

Executive Summary

CERT-UA has uncovered a targeted operation employing a counterfeit Notepad++ plugin to distribute MATCHBOIL.V2 malware. This activity is attributed to the Russia-aligned UAC-0099 threat group and focuses on Windows platforms. The campaign highlights persistent efforts by state-sponsored actors to exploit trusted software components within the supply chain, posing operational risks to affected environments. Security teams should prioritize identification and monitoring of plugin deployment vectors and associated malware behaviors to manage potential compromise.

SOC Impact

Monitor Windows endpoints for indicators related to MATCHBOIL.V2 and suspicious activity involving Notepad++ plugins. Review telemetry for signs of UAC-0099 tactics and any unusual plugin installations to assess potential exposure.

Plugin Deployment and Malware Activity Validation

  • Identify Windows systems with deployed Notepad++ plugins
  • Review logs for unexpected plugin installation activity
  • Monitor endpoint telemetry for MATCHBOIL.V2 indicators
  • Investigate anomalies associated with UAC-0099 threat patterns
  • Confirm integrity of software supply chain components

Why It Matters

This campaign demonstrates the use of software supply chain deception to compromise Windows endpoints, increasing the risk of infiltration by a state-aligned threat actor.

Source