HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 Malware in UAC‑0099 Campaign

A malicious Notepad++ plugin is being used by the UAC‑0099 threat cluster to install MATCHBOIL.V2 on Windows systems. The campaign highlights gaps in security‑awareness and software‑installation controls that SOC 2 auditors scrutinize.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 Malware in UAC‑0099 Campaign

What Happened — CERT‑UA disclosed a new threat campaign in which a malicious program masquerading as a Notepad++ plugin is used to drop the MATCHBOIL.V2 malware on Windows workstations. The campaign is attributed to the Russia‑aligned threat cluster UAC‑0099, which has a history of weaponizing software‑supply‑chain flaws.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits user‑initiated software installation, a classic failure of access‑control and awareness controls that SOC 2 CC6.1 (Security) expects organizations to mitigate.
  • Continuous evidence of security‑awareness training and policy enforcement is required to demonstrate due diligence during a SOC 2 audit.
  • Mapping this incident to your security‑awareness program provides audit‑ready proof that you’ve addressed the “human” attack surface.

Who Is Affected — Primarily technology‑focused enterprises, software developers, and any organization that permits end‑users to install third‑party IDE plugins (e.g., SaaS, fintech, and professional services).

Recommended Actions

  • Review and tighten policies governing the installation of third‑party development tools; enforce whitelisting where feasible.
  • Verify that all staff have completed up‑to‑date security‑awareness training that covers social‑engineering and malicious‑software delivery via trusted‑looking binaries.
  • Collect evidence of training completion, policy acknowledgment, and endpoint‑monitoring logs as part of your SOC 2 control‑testing artifacts.

Technical Notes — The malicious Notepad++ plugin is delivered via compromised download sites and uses standard Windows execution paths to install MATCHBOIL.V2, a credential‑stealing trojan. No specific CVE is cited; the vector is a supply‑chain style “trusted‑tool” impersonation. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →