Russia-Linked UAC-0099 Behind Notepad++ Malware Push
CERT-UA attributes the fake Notepad++ plugin campaign to UAC-0099, a Russia-aligned group now distributing MATCHBOIL.V2 malware via trojanized archives.
What changed: CERT-UA has attributed the fake Notepad++ plugin campaign to UAC-0099, a Russia-aligned threat cluster with an established track record of targeting Ukrainian entities. The payload has been formally identified as MATCHBOIL.V2. The Hacker News reported July 24, 2026, citing the CERT-UA advisory.
Our July 23 coverage detailed the delivery mechanism — a trojanized archive pairing the legitimate Notepad++ application with a malicious plugin called LunchPoke that establishes persistence on Windows. That analysis still stands. The update here is the named adversary.
What attribution adds
UAC-0099 previously weaponized vulnerabilities in WinRAR to compromise Windows systems, according to CERT-UA’s historical tracking. The move to fake Notepad++ plugins is a delivery pivot, not a new group. The targets are Ukraine-linked organizations; the attack surface changed, the adversary didn’t.
For threat intelligence teams, the named attribution matters: UAC-0099 has an existing indicator set that can now be cross-referenced against this campaign. If your organization already tracks this cluster, pull CERT-UA’s updated IOC set and run it against your endpoint telemetry alongside the LunchPoke-specific indicators from the July 23 advisory.
What to do
The defensive posture hasn’t changed from the original write-up:
- Verify installer sources. Notepad++ should come exclusively from notepad-plus-plus.org, with hashes verified against official release signatures. Any copy arriving via file shares, messaging apps, or internal distribution points is uncontrolled risk.
- Audit plugin directories. Check
%AppData%\Notepad++\plugins\and%ProgramFiles%\Notepad++\plugins\for unexpected DLLs. Anything that doesn’t match an approved, known plugin is worth investigating. - Ingest the IOCs. CERT-UA’s LunchPoke/MATCHBOIL.V2 indicators are available via the CERT-UA advisory referenced in the THN reporting — push them into your detection tooling now if you haven’t already.
If UAC-0099 is on your threat actor watchlist, escalate to your threat intel team for cross-referencing against the cluster’s historical IOCs. That’s the added step attribution makes possible.
Priority call
For most organizations outside Ukraine-adjacent targets: medium priority, no change from yesterday. If you responded to the LunchPoke advisory, you’re covered on the technical side. The attribution update is threat intel enrichment.
If your organization interacts with Ukrainian government, defense, or critical infrastructure entities: this is a tracked adversary operating with state-aligned objectives. The risk profile is different from opportunistic criminal activity. Treat it accordingly.
Sources
- The Hacker News, 2026-07-24: Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
- Prior coverage: CERT-UA: LunchPoke Malware Hides in Notepad++ Plugin
Found this useful? Share it.


