INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
UAC-0099 Malware Targets Ukrainian Organizations via Fake Plugin
| 2026-07-24 09:54 CRITICAL HIGHExecutive Summary AI-generated
The Russia-aligned threat actor UAC-0099 has been linked to a phishing campaign targeting Ukrainian organizations, utilizing tactics such as double extortion and sabotage. The CERT-UA advisory recommends updating software versions like WinRAR, 7-Zip, and Notepad++ to their latest versions to close known vulnerabilities exploited by Laundry Bear, another Russia-linked actor.
Technical Mitigations AI-generated
I can provide the technical mitigations in bullet points as requested. However, please note that the provided articles contain sensitive information about malware and threat actors, which may not be suitable for all audiences.
Here are 3-5 technical mitigations:
* Use of secure software updates: Regularly update your operating system, browser, and other software to ensure you have the latest security patches and features.
* Avoid suspicious links and attachments: Be cautious when clicking on links or opening attachments from unknown sources. Verify the authenticity of emails and messages before responding or taking action.
* Use antivirus software: Install and regularly update antivirus software to detect and remove malware threats.
* Keep your system and applications up-to-date: Ensure that all installed systems, browsers, and other applications are current with the latest security patches and features.
* Implement a firewall: Enable the firewall on your computer or device to block unauthorized access from external sources.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation RoundPressOperation RoundPressOperation RoundishOperation Roundish
APT28APT28
CVE-2026-0740CVE-2026-0740
CVE-2025-7443CVE-2025-7443
CVE-2025-34085CVE-2025-34085
CVE-2021-29441CVE-2021-29441
CVE-2020-36847CVE-2020-36847
CVE-2025-12057CVE-2025-12057
CVE-2026-3844CVE-2026-3844
CVE-2020-25213CVE-2020-25213
CVE-2025-66376CVE-2025-66376
CVE-2026-6433CVE-2026-6433
CVE-2026-1969CVE-2026-1969
CVE-2025-49113CVE-2025-49113
CVE-2025-7852CVE-2025-7852
CVE-2026-8496CVE-2026-8496
CVE-2026-48907CVE-2026-48907
CVE-2026-3300CVE-2026-3300
Target & Sectors
CIS
CIS
NORTH_AMERICA
NORTH_AMERICA
telecommunicationstelecommunications
technologytechnology
governmentgovernment
logisticslogistics
Incident Timeline
at least mid-2022
Threat actors used a fake Notepad++ plugin to target the UAC-0099 vulnerability in Microsoft Office applications.
Click on any entity below to view its context and source!
target_region
Russian Federation
CERT-UA published a new advisory attributing a phishing campaign to
UAC-0099
, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting
WinRAR
vulnerabilities and using phishing emails to deliver malware families including
LONEPAGE
,
MATCHBOIL
, and
DRAGSTARE
.
tactic
Phishing
CERT-UA published a new advisory attributing a phishing campaign to
UAC-0099
, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting
WinRAR
vulnerabilities and using phishing emails to deliver malware families including
LONEPAGE
,
MATCHBOIL
, and
DRAGSTARE
.
infrastructure
Winrar
CERT-UA published a new advisory attributing a phishing campaign to
UAC-0099
, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting
WinRAR
vulnerabilities and using phishing emails to deliver malware families including
LONEPAGE
,
MATCHBOIL
, and
DRAGSTARE
.
attribution
CERT-UA
CERT-UA published a new advisory attributing a phishing campaign to
UAC-0099
, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting
WinRAR
vulnerabilities and using phishing emails to deliver malware families including
LONEPAGE
,
MATCHBOIL
, and
DRAGSTARE
.
April 2025
Threat actors linked the SNOWLIGHT-to-VShell chain to China's UNC5174 state group in April 2025.
Click on any entity below to view its context and source!
source_region
China
Those two tools have a history: in April 2025,
Sysdig
linked this SNOWLIGHT-to-VShell chain to the suspected Chinese state group UNC5174, activity
THN covered at the time
.
organisation
THN
Those two tools have a history: in April 2025,
Sysdig
linked this SNOWLIGHT-to-VShell chain to the suspected Chinese state group UNC5174, activity
THN covered at the time
.
May 2025
Threat actors exploited the UAC-0099 vulnerability in Fake Notepad++ plugins.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Since originally exposed by ESET in May 2025, the
campaign
has expanded in scope to target Kerio Webmail and SOGo Webmail, alongside Zimbra, mDaemon, and Roundcube.
organisation
ESET
Since originally exposed by ESET in May 2025, the
campaign
has expanded in scope to target Kerio Webmail and SOGo Webmail, alongside Zimbra, mDaemon, and Roundcube.
organisation
mDaemon
Since originally exposed by ESET in May 2025, the
campaign
has expanded in scope to target Kerio Webmail and SOGo Webmail, alongside Zimbra, mDaemon, and Roundcube.
at least July 2025
Threat actors used a fake Notepad++ plugin to target UAC-0099 vulnerabilities in Roundcube variants of SpyPress.
Click on any entity below to view its context and source!
tactic
Phishing
This campaign arrives alongside a separate U.S.
government advisory
documenting
Laundry Bear
, another Russia-linked actor, running a phishing campaign against Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
The disclosure comes as the U.S. government
highlighted
a phishing campaign orchestrated by the Russia-linked threat actor called
Laundry Bear
(aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
source_region
Russian Federation
This campaign arrives alongside a separate U.S.
government advisory
documenting
Laundry Bear
, another Russia-linked actor, running a phishing campaign against Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
The disclosure comes as the U.S. government
highlighted
a phishing campaign orchestrated by the Russia-linked threat actor called
Laundry Bear
(aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
industry
Government
This campaign arrives alongside a separate U.S.
government advisory
documenting
Laundry Bear
, another Russia-linked actor, running a phishing campaign against Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
The disclosure comes as the U.S. government
highlighted
a phishing campaign orchestrated by the Russia-linked threat actor called
Laundry Bear
(aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
attribution
Laundry Bear
This campaign arrives alongside a separate U.S.
government advisory
documenting
Laundry Bear
, another Russia-linked actor, running a phishing campaign against Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
The disclosure comes as the U.S. government
highlighted
a phishing campaign orchestrated by the Russia-linked threat actor called
Laundry Bear
(aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
attribution
CL-STA-1114
The disclosure comes as the U.S. government
highlighted
a phishing campaign orchestrated by the Russia-linked threat actor called
Laundry Bear
(aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
infrastructure
Roundcube
"Since at least July 2025, TA458 began removing stealing components, and swapping in interactive backdoor mechanisms to its Roundcube variant of SpyPress, to enable long-term access to the instance," Proofpoint researchers said.
organisation
SpyPress
"Since at least July 2025, TA458 began removing stealing components, and swapping in interactive backdoor mechanisms to its Roundcube variant of SpyPress, to enable long-term access to the instance," Proofpoint researchers said.
March 2026
Threat actors exploited zero-day vulnerabilities in Kerio and the SOGo webmail platform to gain unauthorized access.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-8496
In March 2026, the hacking group is said to have exploited zero-day vulnerabilities in Kerio and the SOGo webmail platform (
CVE-2026-8496
).
target_region
Russian Federation
In March 2026, the same research shop caught Russia's Fancy Bear (APT28) the same way: a forgotten open directory spilled the group's phishing tools and logs, in a campaign Hunt.io called
Operation Roundish
.
tactic
Phishing
In March 2026, the same research shop caught Russia's Fancy Bear (APT28) the same way: a forgotten open directory spilled the group's phishing tools and logs, in a campaign Hunt.io called
Operation Roundish
.
threat_actor
APT28
In March 2026, the same research shop caught Russia's Fancy Bear (APT28) the same way: a forgotten open directory spilled the group's phishing tools and logs, in a campaign Hunt.io called
Operation Roundish
.
campaign
Operation Roundish
In March 2026, the same research shop caught Russia's Fancy Bear (APT28) the same way: a forgotten open directory spilled the group's phishing tools and logs, in a campaign Hunt.io called
Operation Roundish
.
organisation
Fancy Bear
In March 2026, the same research shop caught Russia's Fancy Bear (APT28) the same way: a forgotten open directory spilled the group's phishing tools and logs, in a campaign Hunt.io called
Operation Roundish
.
early May 2026
SOCRadar discovered the crew exploited UAC-0099 vulnerability in corporate Java systems before launching a noisy WordPress attack.
Click on any entity below to view its context and source!
organisation
SOCRadar
SOCRadar found that before the noisy WordPress spree, the same crew ran a quieter campaign in early May 2026 against corporate Java systems.
June 11, 2026
Threat actors exploited UAC-0099 vulnerability in Fake Notepad++ plugin on a rented US-based server.
Click on any entity below to view its context and source!
target_region
United States
SOCRadar's threat intelligence team spotted it on June 11, 2026, on a US-based rented server at 137.175.93[.]126 with no password on it at all.
attribution
SOCRadar
SOCRadar's threat intelligence team spotted it on June 11, 2026, on a US-based rented server at 137.175.93[.]126 with no password on it at all.
June 22, weeks
Ctrl-Alt-Intel exploited UAC-0099 vulnerability in Notepad++ on Hunt.io's open-directory platform.
Click on any entity below to view its context and source!
organisation
Ctrl-Alt-Intel
Ctrl-Alt-Intel
had analyzed the same directory too, having found it on Hunt.io's open-directory platform, and published on June 22, weeks before SOCRadar's own July 9 writeup.
July 4
Threat actors exploited UAC-0099 vulnerability in Notepad++ by deleting a batch of log lines sometime between 2 July and 4 July.
Click on any entity below to view its context and source!
general_metric
2 July
When it finally noticed it had been spotted, sometime between July 2 and July 4, it deleted a batch of log lines.
July 9
Threat actors exploited UAC-0099 vulnerability in Notepad++ by using the "Ctrl-Alt-Intel" exploit tool.
Click on any entity below to view its context and source!
organisation
Ctrl-Alt-Intel
Ctrl-Alt-Intel
had analyzed the same directory too, having found it on Hunt.io's open-directory platform, and published on June 22, weeks before SOCRadar's own July 9 writeup.
2026/07/10
Threat actors used a fake Notepad++ plugin to exploit the UAC-0099 vulnerability in targeted software.
2026/07/24
The hacker used a "half-click" exploit to deliver malicious JavaScript called ZimReaper, which can harvest email communications without requiring the victim to click anything beyond opening a malicious email in a vulnerable webmail client.
Click on any entity below to view its context and source!
infrastructure
Winrar
The activity has been attributed by the agency to a threat cluster it tracks as
UAC-0099
, a
Russia-aligned group
that has previously observed weaponizing security flaws in WinRAR software to deliver a malware strain called LONEPAGE.
The U.S. government’s assessment of Laundry Bear’s intent is unambiguous:
CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to their latest versions to close known vulnerabilities that groups like UAC-0099 use to facilitate follow-on stages once they’ve established a foothold.
That archive contains a full working copy of Notepad++ version 8.8.3, a malicious DLL plugin named NppExport.dll, a password-protected RAR archive called updater.rar, and a legitimate WinRAR executable.
“The archive contains a full set of Notepad++ program components version 8.8.3, as well as the “/plugins/NppExport/” directory, which contains a third-party plugin library “NppExport.dll”, a password-protected archive “updater.rar” and the WinRAR executable file “winrar.exe”.”
The malicious DLL, codenamed LUNCHPOKE by CERT-UA, uses the bundled WinRAR binary to unpack the password-protected archive.
The campaign’s use of a bundled legitimate WinRAR executable rather than relying on one already installed is notable: it means the attack chain doesn’t depend on the victim having a vulnerable version present, which makes the update recommendation more relevant as a general hygiene measure than as a specific remediation for this particular campaign.
A password-protected archive ("updater.rar")
Legitimate WinRAR executable ("winrar.exe")
CERT-UA is recommending that organizations update their WinRAR, 7-Zip, and Notepad++ software to the latest versions to prevent threat actors from exploiting any known vulnerabilities to facilitate follow-on attacks.
threat_actor
APT28
TA458 has been described as likely a Russian military intelligence operation without any overlaps with APT28 (aka TA422).
It's worth noting that the campaign is different from
Operation Roundish
, which was disclosed by Hunt.io back in March and uses longstanding infrastructure that CERT-UA
attributed to APT28
in 2024.
organisation
MATCHWOK
Other cyber attacks mounted by the adversary have
employed
phishing emails as an initial access method to deploy MATCHBOIL, MATCHWOK, and DRAGSTARE.
infrastructure
7 Zip
The U.S. government’s assessment of Laundry Bear’s intent is unambiguous:
CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to their latest versions to close known vulnerabilities that groups like UAC-0099 use to facilitate follow-on stages once they’ve established a foothold.
CERT-UA is recommending that organizations update their WinRAR, 7-Zip, and Notepad++ software to the latest versions to prevent threat actors from exploiting any known vulnerabilities to facilitate follow-on attacks.
infrastructure
8.8.3
That archive contains a full working copy of Notepad++ version 8.8.3, a malicious DLL plugin named NppExport.dll, a password-protected RAR archive called updater.rar, and a legitimate WinRAR executable.
“The archive contains a full set of Notepad++ program components version 8.8.3, as well as the “/plugins/NppExport/” directory, which contains a third-party plugin library “NppExport.dll”, a password-protected archive “updater.rar” and the WinRAR executable file “winrar.exe”.”
The archive includes multiple components -
A complete copy of the legitimate editor Notepad++ version 8.8.3
A malicious DLL plugin ("NppExport.dll")
organisation
DLL
That archive contains a full working copy of Notepad++ version 8.8.3, a malicious DLL plugin named NppExport.dll, a password-protected RAR archive called updater.rar, and a legitimate WinRAR executable.
The archive includes multiple components -
A complete copy of the legitimate editor Notepad++ version 8.8.3
A malicious DLL plugin ("NppExport.dll")
organisation
RAR
That archive contains a full working copy of Notepad++ version 8.8.3, a malicious DLL plugin named NppExport.dll, a password-protected RAR archive called updater.rar, and a legitimate WinRAR executable.
Codenamed LUNCHPOKE, the DLL is designed to unpack the RAR archive, which contains "RemoteLibUpdater.exe" and "InitTest.dll," to a specific directory, set up persistence by means of a scheduled task to run "RemoteLibUpdater.exe" every three minutes.
organisation
WinRAR
“The archive contains a full set of Notepad++ program components version 8.8.3, as well as the “/plugins/NppExport/” directory, which contains a third-party plugin library “NppExport.dll”, a password-protected archive “updater.rar” and the WinRAR executable file “winrar.exe”.”
organisation
Legitimate WinRAR
A password-protected archive ("updater.rar")
Legitimate WinRAR executable ("winrar.exe")
infrastructure
Windows
The Computer Emergency Response Team of Ukraine (CERT-UA) has
warned
of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems.
organisation
NATO
Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first-both as a priority target and as a test bench for malicious cyber techniques before broader global deployment.
organisation
Evernote.zip
A legitimate decoy PDF downloads and opens in front of the victim to hold their attention, while in the background the script fetches a second archive called Evernote.zip.
Attempting to launch it will cause a decoy PDF to be downloaded and displayed to the victim as a distraction mechanism, while it silently downloads a second archive named "Evernote.zip."
organisation
LUNCHPOKE
“The file “NppExport.dll” is classified as a LUNCHPOKE utility , the main purpose of which is to create the directory ” %PUBLIC%\Libraries\fFthY3-Ytrevc3w-ab3\ “, extract the contents of the archive “updater.rar” to it using a password (in particular, the files “RemoteLibUpdater.exe” and “InitTest.dll”), copy the standard utility “schtasks.exe” to the file ” %PUBLIC%\Wallpapers\Background.exe ” and create a scheduled task with the name ” \W1n3r-U09oTy-Ap5\Updates ” to run the file ” %PUBLIC%\Libraries\fFthY3-Ytrevc3w-ab3\RemoteLibUpdater.exe ” with the arguments “setup nodisplay” every three minutes (the name of the directory ” fFthY3-Ytrevc3w-ab3 ” changes).”
organisation
InitTest.dll
Codenamed LUNCHPOKE, the DLL is designed to unpack the RAR archive, which contains "RemoteLibUpdater.exe" and "InitTest.dll," to a specific directory, set up persistence by means of a scheduled task to run "RemoteLibUpdater.exe" every three minutes.
That archive contains two files: RemoteLibUpdater.exe and InitTest.dll.
organisation
BURNYBEAR
RemoteLibUpdater.exe is BURNYBEAR, a loader whose job is to execute InitTest.dll.
The "RemoteLibUpdater.exe" binary is BURNYBEAR, which serves as a loader for "InitTest.dll," a modified version of
MATCHBOIL
, a C#-based loader capable of delivering secondary payloads.
organisation
C#-based
The "RemoteLibUpdater.exe" binary is BURNYBEAR, which serves as a loader for "InitTest.dll," a modified version of
MATCHBOIL
, a C#-based loader capable of delivering secondary payloads.
That DLL is a modified version of MATCHBOIL, a C#-based loader capable of fetching and running additional payloads, now designated MATCHBOIL.V2.
organisation
RAM
However, if “RemoteLibUpdater.exe” is launched incorrectly, namely without specifying arguments, BURNYBEAR instead activates logic designed to exhaust computer resources (RAM and CPU).”
organisation
CPU
However, if “RemoteLibUpdater.exe” is launched incorrectly, namely without specifying arguments, BURNYBEAR instead activates logic designed to exhaust computer resources (RAM and CPU).”
organisation
CVE-2025-66376
That campaign uses a “half-click” exploit abusing
CVE-2025-66376
to deliver malicious JavaScript called ZimReaper, which can harvest email communications without requiring the victim to click anything beyond opening a malicious email in a vulnerable webmail client.
organisation
ZimReaper
That campaign uses a “half-click” exploit abusing
CVE-2025-66376
to deliver malicious JavaScript called ZimReaper, which can harvest email communications without requiring the victim to click anything beyond opening a malicious email in a vulnerable webmail client.
The campaign employs a novel "half-click" exploit that abuses CVE-2025-66376 to deliver malicious JavaScript dubbed ZimReaper capable of harvesting email communications and other sensitive data.
organisation
CVE-2025
The campaign employs a novel "half-click" exploit that abuses CVE-2025-66376 to deliver malicious JavaScript dubbed ZimReaper capable of harvesting email communications and other sensitive data.
organisation
Operation RoundPress
"TA458 continues to use SpyPress - an obfuscated JavaScript-based malware seen in Operation RoundPress - which the adversary modifies based on the targeted mail server."
organisation
VBScript
Inside the ZIP is a VBScript file disguised as a PDF document.
The ZIP file contains a Visual Basic Script (VBScript) that masquerades as a PDF document.
organisation
PDF
Inside the ZIP is a VBScript file disguised as a PDF document.
The ZIP file contains a Visual Basic Script (VBScript) that masquerades as a PDF document.
organisation
MATCHBOIL
That DLL is a modified version of MATCHBOIL, a C#-based loader capable of fetching and running additional payloads, now designated MATCHBOIL.V2.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Notepad++)
infrastructure
Roundcube
"SpyPress uses a second Roundcube exploit (CVE-2025-49113) that abuses Roundcube's file upload handler to trigger unsafe PHP deserialization.
organisation
PHP
"SpyPress uses a second Roundcube exploit (CVE-2025-49113) that abuses Roundcube's file upload handler to trigger unsafe PHP deserialization.
WordPress and Joomla, also check:
ThemeREX Addons (CVE-2026-1969), Simple File List (CVE-2020-36847), Custom CSS JS PHP (CVE-2026-6433), BerqWP (CVE-2025-7443), Ninja Forms uploads (CVE-2026-0740), WavePlayer (CVE-2025-12057), WPBookit (CVE-2025-7852), and WP File Manager (CVE-2020-25213).
infrastructure
5.12.8
It was subsequently patched in version 5.12.8.
organisation
CVE-2025-7443
WordPress and Joomla, also check:
ThemeREX Addons (CVE-2026-1969), Simple File List (CVE-2020-36847), Custom CSS JS PHP (CVE-2026-6433), BerqWP (CVE-2025-7443), Ninja Forms uploads (CVE-2026-0740), WavePlayer (CVE-2025-12057), WPBookit (CVE-2025-7852), and WP File Manager (CVE-2020-25213).
organisation
Simple File List
WordPress and Joomla, also check:
ThemeREX Addons (CVE-2026-1969), Simple File List (CVE-2020-36847), Custom CSS JS PHP (CVE-2026-6433), BerqWP (CVE-2025-7443), Ninja Forms uploads (CVE-2026-0740), WavePlayer (CVE-2025-12057), WPBookit (CVE-2025-7852), and WP File Manager (CVE-2020-25213).
organisation
Custom CSS JS
WordPress and Joomla, also check:
ThemeREX Addons (CVE-2026-1969), Simple File List (CVE-2020-36847), Custom CSS JS PHP (CVE-2026-6433), BerqWP (CVE-2025-7443), Ninja Forms uploads (CVE-2026-0740), WavePlayer (CVE-2025-12057), WPBookit (CVE-2025-7852), and WP File Manager (CVE-2020-25213).
organisation
WavePlayer
WordPress and Joomla, also check:
ThemeREX Addons (CVE-2026-1969), Simple File List (CVE-2020-36847), Custom CSS JS PHP (CVE-2026-6433), BerqWP (CVE-2025-7443), Ninja Forms uploads (CVE-2026-0740), WavePlayer (CVE-2025-12057), WPBookit (CVE-2025-7852), and WP File Manager (CVE-2020-25213).
organisation
WPBookit
WordPress and Joomla, also check:
ThemeREX Addons (CVE-2026-1969), Simple File List (CVE-2020-36847), Custom CSS JS PHP (CVE-2026-6433), BerqWP (CVE-2025-7443), Ninja Forms uploads (CVE-2026-0740), WavePlayer (CVE-2025-12057), WPBookit (CVE-2025-7852), and WP File Manager (CVE-2020-25213).
organisation
WP File
WordPress and Joomla, also check:
ThemeREX Addons (CVE-2026-1969), Simple File List (CVE-2020-36847), Custom CSS JS PHP (CVE-2026-6433), BerqWP (CVE-2025-7443), Ninja Forms uploads (CVE-2026-0740), WavePlayer (CVE-2025-12057), WPBookit (CVE-2025-7852), and WP File Manager (CVE-2020-25213).
organisation
UAC-0099 Attacks
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks.
organisation
CVE
In the case of Kerio, no CVE was issued as the webmail product was old and outdated.
organisation
IP
One loose end stands out: a single IP address in Taiwan made more than 42,000 requests downloading the crew's own tools.
data_breach
613 configuration files
It pulled 613 configuration files from 11 systems across nine companies in fintech, e-commerce, logistics, gaming, and electronics.
victims
45,000 targets
The biggest producer was a bug in the Breeze caching plugin (CVE-2026-3844), which the crew fired at more than 45,000 targets and, by its own count, backdoored over 17,000 of them.
infrastructure
2.4.5
WordPress and Joomla, first:
patch Breeze (CVE-2026-3844, fixed in 2.4.5) if the non-default "Host Files Locally – Gravatars" setting is on; it produced the most backdoors here.
organisation
BestShell
The tooling and an earlier campaign
The main backdoor, a file named down.php, was heavily obfuscated, four layers deep, and appears to be derived from an open-source Chinese webshell called BestShell.
organisation
FOFA
The crew took publicly known bugs in website plugins, most of them in WordPress, and built automated scanners to fire those exploits at massive target lists pulled from FOFA, a Chinese search engine for internet-connected systems, similar to Shodan.
Where a site ran a vulnerable version, the exploit could upload a webshell: a small script that lets the attacker run commands on the server from anywhere, read files, steal passwords, and move deeper into the network.
infrastructure
2.9.99
Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA's actively-exploited list, even though it barely landed in this campaign.
organisation
WordPress
The strongest activity hit WordPress sites running out-of-date plugins.
organisation
Breeze
If you run WordPress or Joomla, the two flaws that mattered most were in the Breeze caching plugin and Joomla's JCE editor; skip to the checklist below if that's you.
organisation
JCE
If you run WordPress or Joomla, the two flaws that mattered most were in the Breeze caching plugin and Joomla's JCE editor; skip to the checklist below if that's you.
organisation
MB
Inside was roughly 800MB across 434 files: webshells, exploit scripts, scan results, the operator's typed command history, and command-and-control settings.
data_breach
800 MB
Inside was roughly 800MB across 434 files: webshells, exploit scripts, scan results, the operator's typed command history, and command-and-control settings.
data_breach
434 files
Inside was roughly 800MB across 434 files: webshells, exploit scripts, scan results, the operator's typed command history, and command-and-control settings.
organisation
Ctrl-Alt-Intel's
The number actually compromised was far smaller, and the two research teams measured it differently: Ctrl-Alt-Intel's deduplicated count found 25,195 sites with confirmed or validated compromise evidence, while SOCRadar, counting active webshells, put the live figure at 5,700-plus.
organisation
VShell
For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
organisation
AWS
The haul included cloud login keys for AWS, Alibaba Cloud, Oracle, Tencent, and DigitalOcean, database passwords, and Alipay RSA private keys.
organisation
XXL-Job
XXL-Job and Spring Boot:
close unauthenticated executor endpoints and disable /actuator/heapdump in production.
organisation
The Hacker News
The Hacker News has reached out to SOCRadar for further details on their findings and will update this story with any response.
victims
587,034 Joomla targets
The single largest file was a list of 587,034 Joomla targets.
victims
560,000 targets
One flaw shows the gap plainly: a Joomla bug was fired at more than 560,000 targets but landed on only 77 of them.
Tactical Metrics
Metrics
infrastructure
Winrar
Affected Product
Click for context!
CERT-UA published a new advisory attributing a phishing campaign to
UAC-0099
, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting
WinRAR
vulnerabilities and using phishing emails to deliver malware families including
LONEPAGE
,
MATCHBOIL
, and
DRAGSTARE
.
The U.S. government’s assessment of Laundry Bear’s intent is unambiguous:
CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to their latest versions to close known vulnerabilities that groups like UAC-0099 use to facilitate follow-on stages once they’ve established a foothold.
That archive contains a full working copy of Notepad++ version 8.8.3, a malicious DLL plugin named NppExport.dll, a password-protected RAR archive called updater.rar, and a legitimate WinRAR executable.
“The archive contains a full set of Notepad++ program components version 8.8.3, as well as the “/plugins/NppExport/” directory, which contains a third-party plugin library “NppExport.dll”, a password-protected archive “updater.rar” and the WinRAR executable file “winrar.exe”.”
The malicious DLL, codenamed LUNCHPOKE by CERT-UA, uses the bundled WinRAR binary to unpack the password-protected archive.
The campaign’s use of a bundled legitimate WinRAR executable rather than relying on one already installed is notable: it means the attack chain doesn’t depend on the victim having a vulnerable version present, which makes the update recommendation more relevant as a general hygiene measure than as a specific remediation for this particular campaign.
The activity has been attributed by the agency to a threat cluster it tracks as
UAC-0099
, a
Russia-aligned group
that has previously observed weaponizing security flaws in WinRAR software to deliver a malware strain called LONEPAGE.
A password-protected archive ("updater.rar")
Legitimate WinRAR executable ("winrar.exe")
CERT-UA is recommending that organizations update their WinRAR, 7-Zip, and Notepad++ software to the latest versions to prevent threat actors from exploiting any known vulnerabilities to facilitate follow-on attacks.
Metrics
infrastructure
7
Zip
The U.S. government’s assessment of Laundry Bear’s intent is unambiguous:
CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to their latest versions to close known vulnerabilities that groups like UAC-0099 use to facilitate follow-on stages once they’ve established a foothold.
CERT-UA is recommending that organizations update their WinRAR, 7-Zip, and Notepad++ software to the latest versions to prevent threat actors from exploiting any known vulnerabilities to facilitate follow-on attacks.
Metrics
infrastructure
8.8.3
Software Version
That archive contains a full working copy of Notepad++ version 8.8.3, a malicious DLL plugin named NppExport.dll, a password-protected RAR archive called updater.rar, and a legitimate WinRAR executable.
“The archive contains a full set of Notepad++ program components version 8.8.3, as well as the “/plugins/NppExport/” directory, which contains a third-party plugin library “NppExport.dll”, a password-protected archive “updater.rar” and the WinRAR executable file “winrar.exe”.”
The archive includes multiple components -
A complete copy of the legitimate editor Notepad++ version 8.8.3
A malicious DLL plugin ("NppExport.dll")
Metrics
infrastructure
Windows
Affected Product
The Computer Emergency Response Team of Ukraine (CERT-UA) has
warned
of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems.
Metrics
infrastructure
Roundcube
Affected Product
Since originally exposed by ESET in May 2025, the
campaign
has expanded in scope to target Kerio Webmail and SOGo Webmail, alongside Zimbra, mDaemon, and Roundcube.
"Since at least July 2025, TA458 began removing stealing components, and swapping in interactive backdoor mechanisms to its Roundcube variant of SpyPress, to enable long-term access to the instance," Proofpoint researchers said.
"SpyPress uses a second Roundcube exploit (CVE-2025-49113) that abuses Roundcube's file upload handler to trigger unsafe PHP deserialization.
Metrics
infrastructure
5.12.8
Software Version
It was subsequently patched in version 5.12.8.
Metrics
data_breach
613
Configuration Files
It pulled 613 configuration files from 11 systems across nine companies in fintech, e-commerce, logistics, gaming, and electronics.
Metrics
victims
45,000
Targets
The biggest producer was a bug in the Breeze caching plugin (CVE-2026-3844), which the crew fired at more than 45,000 targets and, by its own count, backdoored over 17,000 of them.
Metrics
infrastructure
2.4.5
Software Version
WordPress and Joomla, first:
patch Breeze (CVE-2026-3844, fixed in 2.4.5) if the non-default "Host Files Locally – Gravatars" setting is on; it produced the most backdoors here.
Metrics
infrastructure
2.9.99
Software Version
Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA's actively-exploited list, even though it barely landed in this campaign.
Metrics
data_breach
800
Mb
Inside was roughly 800MB across 434 files: webshells, exploit scripts, scan results, the operator's typed command history, and command-and-control settings.
Metrics
data_breach
434
Files
Inside was roughly 800MB across 434 files: webshells, exploit scripts, scan results, the operator's typed command history, and command-and-control settings.
Metrics
victims
587,034
Joomla Targets
The single largest file was a list of 587,034 Joomla targets.
Metrics
victims
560,000
Targets
One flaw shows the gap plainly: a Joomla bug was fired at more than 560,000 targets but landed on only 77 of them.
Intelligence Sources
The Hacker News
2026-07-10
The Hacker News
2026-07-24
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Hacker News
Security Affairs
2026-07-24
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-25T06:32
Comprehensive Tactical Telemetry
Highly Correlated Entities
49x
organisation
Identified Entity
Evernote.zip
entity
17x
timeline
Temporal Reference
at least mid-2022
date
16x
vulnerability
Exploited CVE
CVE-2025-66376
cve
14x
attribution
Attributing Entity
CERT-UA
authority
9x
target region
Target Country
Russian Federation
country
6x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
4x
tactic
Cyber Operation Type
Phishing
tactic
4x
industry
Targeted Sector
Government
sector
4x
infrastructure
Software Version
8.8.3
version
3x
infrastructure
Affected Product
Winrar
software
2x
source region
Origin Country
Russian Federation
country
2x
campaign
Campaign
Operation RoundPress
operation
2x
victims
Targets
45,000
targets
Contextual Telemetry
Context Block
13 METRICS
infrastructure
Zip
7
zip
threat actor
APT Group
APT28
actor
general metric
Requests
42,000
requests
data breach
Configuration Files
613
configuration files
general metric
Systems
11
systems
data breach
Mb
800
mb
data breach
Files
434
files
general metric
Sites
25,195
sites
general metric
Plus
5,700
plus
general metric
July
2
july
general metric
Websites
1,400,000
websites
general metric
Known Flaws
27
known flaws
victims
Joomla Targets
587,034
joomla targets
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.