CERT-UA warned that the UAC-0099 threat cluster has shifted its delivery chain against organizations in Ukraine, using phishing emails with image attachments and shortened links to deliver ZIP archives containing a double-extension VBS file. That script retrieves a decoy document and an archive bundling a legitimate Notepad++ 8.8.3 installer with a malicious NppExport.dll, abusing the editor’s normal plugin-loading behavior rather than a supply-chain compromise or software vulnerability. The archive also includes additional components such as updater.rar and, in some cases, WinRAR, which the malware can also fetch from Dropbox if it is not already present.
Once launched, the fake Notepad++ plugin installs LunchPoke, which extracts a password-protected archive, creates persistence through a scheduled task, and starts BurnyBear to load InitTest.dll, a modified MatchBoil V2 implant. CERT-UA said MatchBoil V2 continues to receive updated configuration data, including command-and-control infrastructure and follow-on payloads; published indicators include the domain kaufen-qpon[.]icu and IP 64.94.84[.]204. The agency added that UAC-0099 has previously been linked to initial access activity associated with APT44 (Sandworm) operations.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
CERT-UA released technical details and indicators of compromise for the campaign, including file, network, and host indicators. The report identified infrastructure such as the C2 domain kaufen-qpon[.]icu and IP address 64.94.84[.]204.
CERT-UA reported that in mid-summer 2026 the UAC-0099 threat cluster changed its tactics, techniques, and procedures, using phishing emails with image attachments, shortened URLs, and ZIP archives containing a double-extension VBS script. The updated chain abuses a legitimate Notepad++ 8.8.3 installation for DLL side-loading and deploys LunchPoke, BurnyBear, and MatchBoil V2.
ESET identified GuardBreaker in a UAC-0099-associated VBS script that included a nonfunctional comment about making a nuclear weapon to trigger AI safety controls and deter analysis. The script was intended to download and install MATCHBOIL malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 59 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.