Fake Notepad++ Plugin Delivers MATCHBOIL.V2 Malware in UAC‑0099 Campaign
What Happened — CERT‑UA disclosed a new threat campaign in which a malicious program masquerading as a Notepad++ plugin is used to drop the MATCHBOIL.V2 malware on Windows workstations. The campaign is attributed to the Russia‑aligned threat cluster UAC‑0099, which has a history of weaponizing software‑supply‑chain flaws.
Why It Matters for Compliance & Audit Readiness
- The attack exploits user‑initiated software installation, a classic failure of access‑control and awareness controls that SOC 2 CC6.1 (Security) expects organizations to mitigate.
- Continuous evidence of security‑awareness training and policy enforcement is required to demonstrate due diligence during a SOC 2 audit.
- Mapping this incident to your security‑awareness program provides audit‑ready proof that you’ve addressed the “human” attack surface.
Who Is Affected — Primarily technology‑focused enterprises, software developers, and any organization that permits end‑users to install third‑party IDE plugins (e.g., SaaS, fintech, and professional services).
Recommended Actions
- Review and tighten policies governing the installation of third‑party development tools; enforce whitelisting where feasible.
- Verify that all staff have completed up‑to‑date security‑awareness training that covers social‑engineering and malicious‑software delivery via trusted‑looking binaries.
- Collect evidence of training completion, policy acknowledgment, and endpoint‑monitoring logs as part of your SOC 2 control‑testing artifacts.
Technical Notes — The malicious Notepad++ plugin is delivered via compromised download sites and uses standard Windows execution paths to install MATCHBOIL.V2, a credential‑stealing trojan. No specific CVE is cited; the vector is a supply‑chain style “trusted‑tool” impersonation. Source: The Hacker News