INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

UAC-0099 Malware Targets Ukrainian Organizations via Fake Plugin

| 2026-07-24 09:54 CRITICAL HIGH
Executive Summary AI-generated
The Russia-aligned threat actor UAC-0099 has been linked to a phishing campaign targeting Ukrainian organizations, utilizing tactics such as double extortion and sabotage. The CERT-UA advisory recommends updating software versions like WinRAR, 7-Zip, and Notepad++ to their latest versions to close known vulnerabilities exploited by Laundry Bear, another Russia-linked actor.
Technical Mitigations AI-generated
I can provide the technical mitigations in bullet points as requested. However, please note that the provided articles contain sensitive information about malware and threat actors, which may not be suitable for all audiences. Here are 3-5 technical mitigations: * Use of secure software updates: Regularly update your operating system, browser, and other software to ensure you have the latest security patches and features. * Avoid suspicious links and attachments: Be cautious when clicking on links or opening attachments from unknown sources. Verify the authenticity of emails and messages before responding or taking action. * Use antivirus software: Install and regularly update antivirus software to detect and remove malware threats. * Keep your system and applications up-to-date: Ensure that all installed systems, browsers, and other applications are current with the latest security patches and features. * Implement a firewall: Enable the firewall on your computer or device to block unauthorized access from external sources.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation RoundPressOperation RoundPressOperation RoundishOperation Roundish APT28APT28 CVE-2026-0740CVE-2026-0740 CVE-2025-7443CVE-2025-7443 CVE-2025-34085CVE-2025-34085 CVE-2021-29441CVE-2021-29441 CVE-2020-36847CVE-2020-36847 CVE-2025-12057CVE-2025-12057 CVE-2026-3844CVE-2026-3844 CVE-2020-25213CVE-2020-25213 CVE-2025-66376CVE-2025-66376 CVE-2026-6433CVE-2026-6433 CVE-2026-1969CVE-2026-1969 CVE-2025-49113CVE-2025-49113 CVE-2025-7852CVE-2025-7852 CVE-2026-8496CVE-2026-8496 CVE-2026-48907CVE-2026-48907 CVE-2026-3300CVE-2026-3300
Target & Sectors
CIS CIS NORTH_AMERICA NORTH_AMERICA telecommunicationstelecommunications technologytechnology governmentgovernment logisticslogistics
Incident Timeline
‎at least mid-2022
Threat actors used a fake Notepad++ plugin to target the UAC-0099 vulnerability in Microsoft Office applications.
target_region Russian Federation
tactic Phishing
infrastructure Winrar
attribution CERT-UA
‎April 2025
Threat actors linked the SNOWLIGHT-to-VShell chain to China's UNC5174 state group in April 2025.
source_region China
organisation THN
‎May 2025
Threat actors exploited the UAC-0099 vulnerability in Fake Notepad++ plugins.
infrastructure Roundcube
organisation ESET
organisation mDaemon
‎at least July 2025
Threat actors used a fake Notepad++ plugin to target UAC-0099 vulnerabilities in Roundcube variants of SpyPress.
tactic Phishing
source_region Russian Federation
industry Government
attribution Laundry Bear
attribution CL-STA-1114
infrastructure Roundcube
organisation SpyPress
‎March 2026
Threat actors exploited zero-day vulnerabilities in Kerio and the SOGo webmail platform to gain unauthorized access.
vulnerability CVE-2026-8496
target_region Russian Federation
tactic Phishing
threat_actor APT28
campaign Operation Roundish
organisation Fancy Bear
‎early May 2026
SOCRadar discovered the crew exploited UAC-0099 vulnerability in corporate Java systems before launching a noisy WordPress attack.
organisation SOCRadar
‎June 11, 2026
Threat actors exploited UAC-0099 vulnerability in Fake Notepad++ plugin on a rented US-based server.
target_region United States
attribution SOCRadar
‎June 22, weeks
Ctrl-Alt-Intel exploited UAC-0099 vulnerability in Notepad++ on Hunt.io's open-directory platform.
organisation Ctrl-Alt-Intel
‎July 4
Threat actors exploited UAC-0099 vulnerability in Notepad++ by deleting a batch of log lines sometime between 2 July and 4 July.
general_metric 2 July
‎July 9
Threat actors exploited UAC-0099 vulnerability in Notepad++ by using the "Ctrl-Alt-Intel" exploit tool.
organisation Ctrl-Alt-Intel
‎2026/07/10
Threat actors used a fake Notepad++ plugin to exploit the UAC-0099 vulnerability in targeted software.
‎2026/07/24
The hacker used a "half-click" exploit to deliver malicious JavaScript called ZimReaper, which can harvest email communications without requiring the victim to click anything beyond opening a malicious email in a vulnerable webmail client.
infrastructure Winrar
threat_actor APT28
organisation MATCHWOK
infrastructure 7 Zip
infrastructure 8.8.3
organisation DLL
organisation RAR
organisation WinRAR
organisation Legitimate WinRAR
infrastructure Windows
organisation NATO
organisation Evernote.zip
organisation LUNCHPOKE
organisation InitTest.dll
organisation BURNYBEAR
organisation C#-based
organisation RAM
organisation CPU
organisation CVE-2025-66376
organisation ZimReaper
organisation CVE-2025
organisation Operation RoundPress
organisation VBScript
organisation PDF
organisation MATCHBOIL
organisation SecurityAffairs
infrastructure Roundcube
organisation PHP
infrastructure 5.12.8
organisation CVE-2025-7443
organisation Simple File List
organisation Custom CSS JS
organisation WavePlayer
organisation WPBookit
organisation WP File
organisation UAC-0099 Attacks
organisation CVE
organisation IP
data_breach 613 configuration files
victims 45,000 targets
infrastructure 2.4.5
organisation BestShell
organisation FOFA
infrastructure 2.9.99
organisation WordPress
organisation Breeze
organisation JCE
organisation MB
data_breach 800 MB
data_breach 434 files
organisation Ctrl-Alt-Intel's
organisation VShell
organisation AWS
organisation XXL-Job
organisation The Hacker News
victims 587,034 Joomla targets
victims 560,000 targets
Tactical Metrics
Metrics
infrastructure
‎Winrar
Affected Product
Metrics
infrastructure
7
Zip
Metrics
infrastructure
‎8.8.3
Software Version
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Roundcube
Affected Product
Metrics
infrastructure
‎5.12.8
Software Version
Metrics
data_breach
613
Configuration Files
Metrics
victims
45,000
Targets
Metrics
infrastructure
‎2.4.5
Software Version
Metrics
infrastructure
‎2.9.99
Software Version
Metrics
data_breach
800
Mb
Metrics
data_breach
434
Files
Metrics
victims
587,034
Joomla Targets
Metrics
victims
560,000
Targets