CERT-UA warned that the UAC-0099 threat cluster has shifted its delivery chain against organizations in Ukraine, using phishing emails with image attachments and shortened links to deliver ZIP archives containing a double-extension VBS file. That script retrieves a decoy document and an archive bundling a legitimate Notepad++ 8.8.3 installer with a malicious NppExport.dll, abusing the editor’s normal plugin-loading behavior rather than a supply-chain compromise or software vulnerability. The archive also includes additional components such as updater.rar and, in some cases, WinRAR, which the malware can also fetch from Dropbox if it is not already present.
Once launched, the fake Notepad++ plugin installs LunchPoke, which extracts a password-protected archive, creates persistence through a scheduled task, and starts BurnyBear to load InitTest.dll, a modified MatchBoil V2 implant. CERT-UA said MatchBoil V2 continues to receive updated configuration data, including command-and-control infrastructure and follow-on payloads; published indicators include the domain kaufen-qpon[.]icu and IP 64.94.84[.]204. The agency added that UAC-0099 has previously been linked to initial access activity associated with APT44 (Sandworm) operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CERT-UA released technical details and indicators of compromise for the campaign, including file, network, and host indicators. The report identified infrastructure such as the C2 domain kaufen-qpon[.]icu and IP address 64.94.84[.]204.
CERT-UA reported that in mid-summer 2026 the UAC-0099 threat cluster changed its tactics, techniques, and procedures, using phishing emails with image attachments, shortened URLs, and ZIP archives containing a double-extension VBS script. The updated chain abuses a legitimate Notepad++ 8.8.3 installation for DLL side-loading and deploys LunchPoke, BurnyBear, and MatchBoil V2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.