Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The UAC-0099 threat cluster, active since at least 2022 and attributed to Russia-aligned operations in Ukraine, distributed a new version of the MATCHBOIL.V2 malware in a summer 2026 campaign via a fake Notepad++ plugin. The technique relies on DLL sideloading: the legitimate, signed, and trusted application automatically loads a malicious library from its own plugin directory, inheriting Windows trust and bypassing traditional security controls. The targets are Ukrainian government and defense entities, following a pattern that CERT-UA researchers and analyses from ESET and Mandiant have observed as a precursor to more destructive operations.
- UAC-0099 distributes MATCHBOIL.V2, an updated C# loader, via phishing emails with an image attachment that redirects to a ZIP archive
- The technical chain involves legitimate Notepad++ 8.8.3, the malicious NppExport.dll DLL (nicknamed LUNCHPOKE), and two subsequent stages: BURNYBEAR and MATCHBOIL.V2
- BURNYBEAR implements an anti-sandbox technique that exhausts RAM/CPU resources if executed without the correct arguments
- Persistence is achieved via a scheduled task that triggers every 3 minutes
The Infection Chain: From Fake PDF to Remote Control
Initial access occurs via a phishing email with an image attachment that redirects, through a URL shortener, to a ZIP archive. As documented by CERT-UA and reported by The Hacker News, the package contains a VBScript disguised as a PDF, which downloads a further archive named 'Evernote.zip'. This archive includes: legitimate Notepad++ 8.8.3, the malicious NppExport.dll (nicknamed LUNCHPOKE), and a password-protected updater.rar file.
When the user launches Notepad++, the application automatically loads NppExport.dll from the plugin directory: this is DLL sideloading, a technique that exploits the legitimate loading of external libraries. LUNCHPOKE extracts updater.rar, generating RemoteLibUpdater.exe (nicknamed BURNYBEAR) and InitTest.dll (MATCHBOIL.V2). At this point, BURNYBEAR activates MATCHBOIL.V2 and establishes persistence.
The MATCHBOIL.V2 loader, as indicated by the source, communicates with command-and-control servers, updates its own configuration, and downloads secondary payloads. TechTimes reports that the new version introduces a dependency on WinRAR for decompression, an element that distinguishes MATCHBOIL.V2 from previous iterations.
BURNYBEAR: The Anti-Sandbox That Burns Resources to Hide
A distinctive trait of the campaign is the environmental defense logic integrated into BURNYBEAR. According to CERT-UA, as reported by The Hacker News:
"At the same time, if 'RemoteLibUpdater.exe' is launched incorrectly, namely without specifying arguments, BURNYBEAR instead activates logic designed to exhaust computer resources (RAM and processor)"
This mechanism serves to thwart automated sandbox analysis: if the executable detects an anomalous execution environment — absence of the expected arguments, typical of a standard analysis — it triggers an intensive RAM and CPU consumption loop. The goal is to make execution in virtualized or resource-constrained environments impractical, filtering out researchers and allowing only real target systems to proceed.
Persistence is guaranteed by a scheduled task that triggers every 3 minutes, an aggressive interval that minimizes windows of opportunity for manual removal.
CVE-2025-56383: When By-Design Becomes Attack Surface
The plugin loading vector is formally identified as CVE-2025-56383, with a CVSS 3.1 score of 8.4 (HIGH), vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H per the NVD record. The technical description in the database is minimal, and the same identifier is contested by the Notepad++ developer, who considers the plugin loading behavior a legitimate architectural mechanism.
This tension — between formal vulnerability and by-design functionality — is the core of the problem for defenses. There is no easy patch: fixing the automatic loading of plugin DLLs would break the extension ecosystem that constitutes one of Notepad++'s strengths. The result is an attack surface recognized by threat actors but not mitigable with traditional vulnerability management tools.
From UAC-0099 to Sandworm: The Bridge to Destruction
UAC-0099 does not operate in isolation. According to ESET and Mandiant analyses reported by TechTimes, the group functions as an initial access broker for APT44/Sandworm, the cluster associated with the Russian GRU already responsible for cyber sabotage operations. In documented cases, UAC-0099 handed over obtained accesses to Sandworm, which used them to deploy wiper malware against universities, energy infrastructure, and the Ukrainian agricultural sector.
This relationship is a historical pattern, not confirmed specifically for the summer 2026 MATCHBOIL.V2 campaign. The dossier does not specify how many systems were compromised in this specific campaign, nor whether the secondary payloads downloaded by MATCHBOIL.V2 already include destructive capabilities or limit their scope to initial collection.
In previous campaigns — documented by CERT-UA in August 2025 — UAC-0099 used the MATCHBOIL loader to distribute the MATCHWOK backdoor and the DRAGSTARE stealer. The technical continuity suggests an instrumental evolution rather than a tactical rupture.
Immediate Actions
- Verify the presence of unsigned NppExport.dll or DLLs with anomalous hashes in Notepad++ plugin directories on systems of interest
- Check for recurring scheduled tasks with a 3-minute interval, particularly those pointing to executables in temporary paths or with generic names like RemoteLibUpdater.exe \li>Keep Notepad++ updated to recent versions while monitoring developments on CVE-2025-56383, bearing in mind the vector is not patchable without impact on the plugin ecosystem
- Isolate systems running Notepad++ in environments handling sensitive defense or government data, considering UAC-0099's specific targeting of these sectors
The campaign requires no zero-day exploit nor software vulnerability: it exploits the normal operation of a widely used application, making detection based on traditional indicators of compromise insufficient without behavioral analysis of the process.
Why Traditional Defense Is No Longer Enough
The MATCHBOIL.V2 case highlights a structural blind spot in enterprise security architectures. Tools that rely on binary signatures or vendor reputation — Notepad++ is legitimate, signed, widely used software — fail when the threat nests in the extension mechanism, not the core code. Windows trust inheritance, whereby a signed process inherits credibility for the libraries it loads, becomes a bridge for execution in this scenario.
For observers of the geopolitical landscape, the UAC-0099/Sandworm pattern has predictive value. Ukraine serves as a test bench for techniques later extended to global targets; the initial compromise, silent and collection-oriented, typically precedes more visible phases. The transition from loader to wiper is not hypothetical: it is documented, even if not confirmed for this specific campaign. The lack of detail on the nature of secondary payloads downloaded by MATCHBOIL.V2 leaves an area of uncertainty that defenses must manage as active risk, not as a remote hypothesis.
Sources
- https://thehackernews.com/2026/10/anthropic-expands-claude-access-for.html
- https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
- https://www.techtimes.com/articles/321558/20260725/fake-notepad-plugin-hides-russian-malware-targeting-ukrainian-defense-teams.htm
- https://nvd.nist.gov/vuln/detail/CVE-2026-8496
- https://nvd.nist.gov/vuln/detail/CVE-2025-56383
- https://thehackernews.com/2025/08/cert-ua-warns-of-hta-delivered-c.html
- https://cert.gov.ua/article/6281123
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.