[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4DEhnUVWNSiPcwolMjtbLWOC1sBMgZFO3C50B-qnJds":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"601182e7-ce7c-4b49-a9ea-d0663d6d2282","fake-notepad-plugin-used-to-deploy-espionage-malware-in-phishing-campaign","df2c1bd1-4d1b-40c6-9704-4a2d0d650ea1","Fake Notepad++ Plugin Used to Deploy Espionage Malware in Phishing Campaign","UAC-0099, a Russia-aligned threat actor, is exploiting user trust in legitimate software by delivering a malicious Notepad++ plugin bundled with a real application installation to avoid suspicion. The attack relies on phishing emails and DLL-based malware delivery, highlighting how supply chain trust and plugin ecosystems can be weaponized against unsuspecting users. Because the malicious DLL is loaded alongside a legitimate tool, traditional signature-based defenses may fail to flag it. This matters because espionage-focused campaigns like this target sensitive organizational data, and the use of trusted application contexts makes detection and user recognition of the threat significantly harder.","**Immediate actions:**\n- Block execution of unsigned or unverified DLL files and plugins using application whitelisting tools such as AppLocker or Windows Defender Application Control.\n- Conduct emergency phishing awareness training focused on malicious attachments and fake software bundles targeting employees.\n- Audit all installed Notepad++ plugins across endpoints and remove any that are not officially sanctioned.\n\n**Long-term improvements:**\n- Establish a vetted, organization-approved software and plugin catalog, restricting installation to verified sources only.\n- Implement a formal third-party and plugin supply chain review process before any software component is permitted in the environment.\n- Enforce least-privilege policies to prevent standard users from installing plugins or running VBScript without administrative approval.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) solutions configured to alert on suspicious DLL sideloading and VBScript execution patterns.\n- Enable centralized logging of process creation events, DLL loads, and email attachment activity to support rapid threat hunting.\n- Subscribe to CERT-UA and relevant threat intelligence feeds to receive timely indicators of compromise associated with UAC-0099 campaigns.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 9 – Email and Web Browser Protections","CIS Control 10 – Malware Defenses","CIS Control 14 – Security Awareness and Skills Training","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 SA-12 – Supply Chain Protection","NIST SP 800-53 AC-6 – Least Privilege","NIST SP 800-53 AU-12 – Audit Record Generation","MITRE ATT&CK T1574.002 – DLL Side-Loading","MITRE ATT&CK T1566 – Phishing","NIST CSF DE.CM-1 – Network and Physical Environment Monitoring","published","2026-07-24T08:20:39.825345+00:00","2026-07-24T08:20:39.734+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Ffake-notepad-plugin-delivers.html","fake-notepad-plugin-delivers-matchboil-v2-in-uac-0099-attacks-852d72","Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]