CuraSec

Plan archived

UAC-0099 hides MatchBoil malware in fake Notepad++ plugin

2026-07-24 12:43 UTC · BleepingComputer · read the source ↗ #malware#windows#threat-actor
  • Engineer — Learn: No patch exists for this — it’s a social-engineering delivery using a legitimate app bundled with a malicious plugin for persistence. Worth understanding the plugin-directory persistence technique when hardening developer workstations.
  • SOC/IR — Plan: UAC-0099 is now deploying MatchBoil v2 and LunchPoke via fake Notepad++ archives; build or tune detections for unauthorized writes to Notepad++ plugin directories and hunt for these malware family names in EDR telemetry.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.