socprime.com/blog/detect-...
socprime.com/blog/detect-...
ESET saw a UAC-0099 VBS comment aimed at stopping an LLM scanner before MATCHBOIL. It did not affect runtime behavior, and public reporting does not show campaign-scale success.
ESET saw a UAC-0099 VBS comment aimed at stopping an LLM scanner before MATCHBOIL. It did not affect runtime behavior, and public reporting does not show campaign-scale success.
CERT-UAは、少なくとも2022年半ばから活動しているロシア系の脅威アクターであるUAC-0099によるフィッシングキャンペーンに関する新たな勧告を発表しました。UAC-0099は、 WinRARの脆弱性を悪用し、フィッシングメールを使用してLONEPAGE、MATCHBOIL、DRAGSTAREなどのマルウェアファミリーを配信することで知られています。
今夏初めに確認された最新の攻撃キャンペーンでは、トロイの木馬化されたNotepad++プラグインが感染メカニズムとし...
CERT-UAは、少なくとも2022年半ばから活動しているロシア系の脅威アクターであるUAC-0099によるフィッシングキャンペーンに関する新たな勧告を発表しました。UAC-0099は、 WinRARの脆弱性を悪用し、フィッシングメールを使用してLONEPAGE、MATCHBOIL、DRAGSTAREなどのマルウェアファミリーを配信することで知られています。
今夏初めに確認された最新の攻撃キャンペーンでは、トロイの木馬化されたNotepad++プラグインが感染メカニズムとし...
📝 ## 🔍 Contexte
Le **CERT-UA** a publié le 21 juille…
https://cyberveille.ch/posts/2026-07-24-uac-0099-nouveaux-outils-lunchpoke-burnybear-et-matchboil-v2-via-dll-hijacking-notepad/ #BURNYBEAR #Cyberveille
📝 ## 🔍 Contexte
Le **CERT-UA** a publié le 21 juille…
https://cyberveille.ch/posts/2026-07-24-uac-0099-nouveaux-outils-lunchpoke-burnybear-et-matchboil-v2-via-dll-hijacking-notepad/ #BURNYBEAR #Cyberveille
https://blindthoughts.com/uac-0099-matchboil-v2-fake-notepad-plugin
#malware #windows #threatintelligence #certua #notepadplusplus
https://blindthoughts.com/uac-0099-matchboil-v2-fake-notepad-plugin
#malware #windows #threatintelligence #certua #notepadplusplus
The UAC-0099 threat group is using a legitimate Notepad++ 8.8.3 executable to sideload malicious DLLs (LunchPoke), eventually deploying the MatchBoil V2 loader.
🛠️ Action required:
Update...
The UAC-0099 threat group is using a legitimate Notepad++ 8.8.3 executable to sideload malicious DLLs (LunchPoke), eventually deploying the MatchBoil V2 loader.
🛠️ Action required:
Update...
Ukraine’s CERT-UA warns of phishing attacks by UAC-0099 targeting defense sectors, using malware like MATCHBOIL, MATCHWOK, and DRAGSTARE. Ukraine’s CERT-UA warns of phishing attacks by threat actor UAC…
#hackernews #news
Ukraine’s CERT-UA warns of phishing attacks by UAC-0099 targeting defense sectors, using malware like MATCHBOIL, MATCHWOK, and DRAGSTARE. Ukraine’s CERT-UA warns of phishing attacks by threat actor UAC…
#hackernews #news
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks carried out by a threat actor called UAC-0099 targeting government agencies, the defense forces, and enterprises of t…
#hackernews #news
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks carried out by a threat actor called UAC-0099 targeting government agencies, the defense forces, and enterprises of t…
#hackernews #news
In a relentless wave of cyberattacks, the Ukrainian National Cybersecurity team CERT-UA has uncovered a highly sophisticated phishing campaign targeting government agencies, military…
In a relentless wave of cyberattacks, the Ukrainian National Cybersecurity team CERT-UA has uncovered a highly sophisticated phishing campaign targeting government agencies, military…
#CERTUA #DRAGSTARE #evidenza #HTA #malware #MATCHBOIL #phishing #UAC0099
www.matricedigitale.it/2025/08/06/u...
#CERTUA #DRAGSTARE #evidenza #HTA #malware #MATCHBOIL #phishing #UAC0099
www.matricedigitale.it/2025/08/06/u...
#APT #Breaking #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Cyber #warfare #Hacking #Malware […]
[Original post on securityaffairs.com]
#APT #Breaking #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Cyber #warfare #Hacking #Malware […]
[Original post on securityaffairs.com]