Executive Summary
In July 2026, the Russia-aligned threat group UAC-0099 initiated a sophisticated phishing campaign targeting Ukrainian organizations. The attack began with emails containing image attachments that, when clicked, redirected victims to download a ZIP archive. This archive included a VBScript disguised as a PDF, which, upon execution, installed a legitimate version of Notepad++ alongside a malicious plugin named LUNCHPOKE. This plugin facilitated the deployment of additional malware components, including BURNYBEAR and MATCHBOIL.V2, establishing persistence and enabling further malicious activities on the compromised systems.
This incident underscores the evolving tactics of threat actors who exploit trusted software to deliver malware, bypassing traditional security measures. The use of legitimate applications like Notepad++ as delivery mechanisms highlights the need for heightened vigilance and advanced detection capabilities to identify and mitigate such sophisticated threats.
Why This Matters Now
The exploitation of widely used software like Notepad++ for malware delivery represents a significant escalation in cyber threat tactics, emphasizing the urgent need for organizations to enhance their security protocols and user awareness to prevent similar attacks.
Attack Path Analysis
The attack began with a phishing email containing an image that, when clicked, redirected the victim to a file-sharing service to download a ZIP archive. This archive contained a VBScript disguised as a PDF document, which, upon execution, downloaded and launched a legitimate Notepad++ application bundled with a malicious plugin. The plugin executed a series of actions to establish persistence and deploy additional malware components, culminating in the installation of MATCHBOIL.V2, a C#-based loader capable of delivering secondary payloads.
Kill Chain Progression
Initial Compromise
Description
The attacker sent a phishing email with an image attachment that, when clicked, redirected the victim to a file-sharing service to download a ZIP archive containing a VBScript disguised as a PDF document.
Related CVEs
CVE-2025-56383
CVSS 8.4DLL hijacking vulnerability in Notepad++ version 8.8.3 allows attackers to execute arbitrary code via malicious plugins.
Affected Products:
Notepad++ Notepad++ – 8.8.3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
Event Triggered Execution: Installer Packages
Hijack Execution Flow: DLL Search Order Hijacking
Command and Scripting Interpreter: Visual Basic
Indicator Removal: File Deletion
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Applications and Workloads
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain attacks targeting development tools like Notepad++ plugins pose critical risks to software integrity, requiring enhanced zero trust segmentation and egress security controls.
Information Technology/IT
UAC-0099's malicious plugin campaign exploits IT infrastructure dependencies, necessitating multicloud visibility, threat detection capabilities, and secure hybrid connectivity for comprehensive protection.
Computer/Network Security
Cybersecurity firms face sophisticated supply chain compromises requiring advanced threat intelligence, inline IPS capabilities, and cloud-native security fabric implementations for effective defense.
Government Administration
State-sponsored attacks from Russia-aligned groups targeting government systems demand encrypted traffic protection, east-west security monitoring, and compliance with NIST frameworks.
Sources
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attackshttps://thehackernews.com/2026/07/fake-notepad-plugin-delivers.htmlVerified
- Hackers abuse Notepad++ plugins to stealthily install malwarehttps://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/Verified
- UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizationshttps://securityaffairs.com/195923/cyber-warfare-2/uac-0099-is-now-hiding-malware-inside-a-fake-notepad-plugin-to-target-ukrainian-organizations.htmlVerified
- UAC-0099 Abuses Notepad++ Plugin Loading to Deploy LunchPoke and MatchBoilhttps://mallory.ai/stories/019f89f3-f476-75be-a6ed-e531a7457b74Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial phishing compromise, it would likely limit the attacker's subsequent network access, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by restricting unauthorized access paths within the network.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict controls on internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by controlling and monitoring outbound data flows.
Aviatrix Zero Trust CNSF would likely reduce the overall impact of the attack by limiting the attacker's reach and ability to exploit additional systems.
Impact at a Glance
Affected Business Functions
- Software Development
- IT Operations
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive internal documents and source code.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict plugin execution and limit unauthorized code execution.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to suspicious plugin activities.
- • Utilize Multicloud Visibility & Control to monitor and manage plugin behaviors across cloud environments.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration by malicious plugins.
- • Regularly update and patch software to mitigate vulnerabilities exploited by malicious plugins.



