CERT UA Warns Of MATCHBOIL V2 Malware Hidden In Fake Notepad Plus Plus Plugin

CERT UA Warns Of MATCHBOIL V2 Malware Hidden In Fake Notepad Plus Plus Plugin

The Computer Emergency Response Team of Ukraine (CERT UA) has disclosed a new cyber campaign in which attackers are distributing a malicious program disguised as a Notepad++ plugin to compromise Windows systems. The activity has been attributed to UAC 0099, a Russia aligned threat group that has remained active since at least mid 2022 and has previously exploited WinRAR vulnerabilities to deploy the LONEPAGE malware. According to CERT UA, the group has also relied on phishing campaigns to distribute malware families including MATCHBOIL, MATCHWOK, and DRAGSTARE. The latest campaign continues that pattern by combining phishing emails, legitimate software, and custom malware to establish persistent access on targeted systems before deploying additional malicious payloads.

Researchers said the attack begins with a phishing email containing an image attachment that directs victims to a shortened URL. The link redirects users to a file sharing platform where a ZIP archive is downloaded. Inside the archive is a Visual Basic Script disguised as a PDF document. When executed, the script downloads and displays a decoy PDF file to distract the victim while silently retrieving another archive named Evernote.zip. That archive contains a legitimate copy of Notepad++ version 8.8.3 alongside a malicious NppExport.dll plugin, a password protected updater.rar archive, and a legitimate WinRAR executable. The VBScript extracts the archive contents and launches Notepad++, causing the malicious DLL, known as LUNCHPOKE, to load automatically. LUNCHPOKE extracts additional files from the protected archive and establishes persistence through a scheduled task that executes RemoteLibUpdater.exe every three minutes.

CERT UA identified RemoteLibUpdater.exe as BURNYBEAR, a loader designed to execute InitTest.dll, a modified version of the C# based MATCHBOIL malware now tracked as MATCHBOIL.V2. The updated loader enables attackers to deliver secondary payloads after compromising a system. Researchers also observed that if BURNYBEAR is executed without the required command line arguments, it activates code intended to exhaust the victim’s system resources by consuming processor power and memory. To reduce exposure to similar attacks, CERT UA recommends organizations update WinRAR, 7 Zip, and Notepad++ to their latest available versions. Although the malware does not rely exclusively on software vulnerabilities, maintaining updated applications reduces opportunities for attackers to exploit known weaknesses during follow on stages of an intrusion.

The disclosure comes as United States government agencies also warned of a separate phishing campaign linked to another Russia associated threat actor known as Laundry Bear. That campaign targets vulnerable Zimbra mail servers using a technique referred to as a half click exploit, which abuses CVE 2025 66376 to deploy JavaScript malware called ZimReaper. Unlike conventional phishing attacks that require victims to click links or open attachments, the exploit activates when a user simply views a malicious email in an affected version of the webmail platform. At the same time, Proofpoint has reported continued activity under Operation RoundPress by threat actor TA458, which has expanded its attacks against multiple webmail platforms including Zimbra, Kerio Webmail, SOGo Webmail, Roundcube, and mDaemon. Researchers said the campaign now uses additional exploits, including CVE 2026 8496 and CVE 2025 49113, to gain remote code execution, install persistent backdoors, and maintain long term access to compromised environments. According to Proofpoint, TA458 primarily targets Ukrainian government agencies along with military and government organizations across Eastern Europe while also conducting limited operations against chemical, telecommunications, and technology companies.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Post Comment