Plan
archived
UAC-0099 hides MatchBoil malware in fake Notepad++ plugin
- Engineer — Learn: No patch exists for this — it’s a social-engineering delivery using a legitimate app bundled with a malicious plugin for persistence. Worth understanding the plugin-directory persistence technique when hardening developer workstations.
- SOC/IR — Plan: UAC-0099 is now deploying MatchBoil v2 and LunchPoke via fake Notepad++ archives; build or tune detections for unauthorized writes to Notepad++ plugin directories and hunt for these malware family names in EDR telemetry.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.