Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
CERT-UA has warned of a new phishing campaign led by the UAC-0099 threat cluster (linked to Russia) utilizing a malicious Notepad++ plugin to deliver the MATCHBOIL.V2 malware. The campaign begins with a phishing email containing a ZIP archive, which, when opened, installs a malicious DLL plugin ('NppExport.dll') and a VBScript. This VBScript then extracts and launches Notepad++, which loads 'NppExport.dll,' which in turn unpacks a RAR archive containing 'RemoteLibUpdater.exe' and 'InitTest.dll.' The latter is a C#-based loader delivering secondary payloads, including a modified version of MATCHBOIL. CERT-UA advises updating WinRAR, 7-Zip, and Notepad++ to mitigate this threat.
CERT-UA has issued a warning regarding a new phishing campaign orchestrated by the UAC-0099 threat cluster, a group linked to Russia. The campaign leverages a malicious Notepad++ plugin to deliver the MATCHBOIL.V2 malware. The initial stage involves a phishing email containing an image attachment. When a user clicks the attachment, a URL is opened, directing them to a file-sharing service like EasySend[.]co to retrieve a ZIP archive.
Inside the ZIP file is a Visual Basic Script (VBScript) that masquerades as a PDF document. Attempting to launch this VBScript causes a decoy PDF to be downloaded and displayed, while it silently downloads a second archive named "Evernote.zip." This archive contains multiple components: a complete copy of the legitimate Notepad++ version 8.8.3, a malicious DLL plugin ("NppExport.dll"), a password-protected archive ("updater.rar"), and the legitimate WinRAR executable ("winrar.exe").
The primary goal of the VBScript is to extract the contents of the archive and launch Notepad++, which, in turn, loads "NppExport.dll." This DLL is designed to unpack the RAR archive, which contains "RemoteLibUpdater.exe" and "InitTest.dll," to a specific directory and set up persistence through a scheduled task to run "RemoteLibUpdater.exe" every three minutes. "RemoteLibUpdater.exe" serves as a loader for "InitTest.dll," a modified version of MATCHBOIL, a C#-based loader capable of delivering secondary payloads.
If 'RemoteLibUpdater.exe' is launched incorrectly, namely without specifying arguments, BURNYBEAR (the loader) activates logic designed to exhaust computer resources (RAM and processor). CERT-UA recommends that organizations update their WinRAR, 7-Zip, and Notepad++ software to the latest versions to prevent threat actors from exploiting any known vulnerabilities to facilitate follow-on attacks. This disclosure comes as the U.S. government highlighted a similar phishing campaign targeting Zimbra mail servers, attributed to the Russia-linked threat actor Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard).
