This Fake Notepad++ Add-On Hides Russian Malware
Ukraine's CERT-UA has warned of a campaign disguising malware as a plugin for Notepad++, the popular free code editor. The activity is attributed to UAC-0099, a Russia aligned group active since 2022. It starts with a phishing email whose image opens a hidden ZIP disguised as a PDF. Behind that decoy, a real copy of Notepad++ loads a hidden plugin that installs MATCHBOIL.V2, a loader that keeps downloading more malware. CERT-UA urges everyone to update Notepad++, WinRAR, and 7-Zip, and to stay cautious with email attachments.
Transcript
A Russia aligned hacking group is disguising malware as a plugin for Notepad++, the popular free code editor.
CERT-UA, Ukraine's cyber emergency team, traced it to UAC-0099, a group active since 2022.
It starts with a phishing email whose image opens a hidden ZIP disguised as a PDF.
Behind the decoy, a real Notepad++ loads a hidden plugin that installs MATCHBOIL.V2, a loader that keeps downloading more malware.
CERT-UA urges everyone to update Notepad++, WinRAR, and 7-Zip, and stay cautious with email attachments.
Inboxsmith helps small businesses handle calls and messages so nothing gets missed. Please like and subscribe for more news.
Sources
Every claim in this video comes from the top ranking coverage of this topic. The claims and where each one came from:
- CERT-UA attributed a campaign using a malicious Notepad++ plugin to the Russia aligned cluster UAC-0099.(CERT-UA official advisory (UAC-0099 / MATCHBOIL.V2))
- The chain loads Notepad++ 8.8.3 with a malicious plugin, establishes persistence via a scheduled task every three minutes, and delivers the MATCHBOIL.V2 loader.(CERT-UA official advisory (UAC-0099 / MATCHBOIL.V2))
- CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to their latest versions.(CERT-UA official advisory (UAC-0099 / MATCHBOIL.V2))
