UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 Malware — Threadlinqs Intelligence
As of 2026-07-23, UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 Malware is a high-severity malware threat attributed to UAC-0099 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1657 · Severity: HIGH · CVSS: 8.4 · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-23 · revalidated 1× · latest source
Attribution: UAC-0099 · Russia · ESPIONAGE
Ukrainian threat cluster UAC-0099, which historically hands off validated targets to APT44/Sandworm, distributes trojanized Notepad++ v8.8.3 archives that bundle a malicious NppExport.dll plugin
In July 2026, BleepingComputer (citing analysis attributed to CERT-UA visibility into Ukrainian-targeted intrusion activity) reported a campaign by UAC-0099, a Ukrainian-focused initial-access cluster active since at least May 2023 that has previously conducted reconnaissance and validated-target handoffs feeding into APT44/Sandworm (aka Iron Viking, Voodoo Bear, Seashell Blizzard, FROZENBARENTS) operations. The campaign trojanizes the popular open-source text editor Notepad++ (legitimate build v8.8.3) by bundling it inside an archive (Evernote.zip) alongside a malicious replacement for the NppExport.dll plugin, a password-protected updater.rar, and a copy of WinRAR.
The infection begins with a VBS script disguised as a PDF document (a classic double-extension / icon-spoofing lure) which, when opened by a victim, retrieves the Evernote.zip archive from attacker infrastructure. The VBS installs the bundled package into a randomly-named directory to evade static path-based detections, then launches Notepad++, which loads the malicious NppExport.dll through the application's standard (and, per the vendor, intentional) plugin-loading mechanism — tracked as CVE-2025-56383, a DLL/plugin-replacement flaw disputed by the Notepad++ team, who characterize it as an abuse of intended functionality requiring local write access to the plugins directory rather than a true vulnerability. The malicious plugin, internally identified by researchers as LunchPoke, creates a scheduled task for persistence and extracts the bundled password-protected updater.rar using the co-delivered WinRAR binary.
Extraction of updater.rar drops RemoteLibUpdater.exe and InitTest.dll, which execute the BurnyBear loader. BurnyBear acts as an intermediate loader for the final payload and additionally includes a fallback resource-exhaustion routine that can drive target RAM/CPU utilization to disrupt or degrade the host if follow-on stages fail to deploy — a denial-of-service capability layered onto what is otherwise a covert-access chain. BurnyBear ultimately loads MatchBoil V2, described as the campaign's final malware loader stage, positioned to receive further second-stage tooling consistent with UAC-0099's historical role of validating and handing off compromised Ukrainian targets to Sandworm/APT44 for follow-on destructive or espionage operations.
CVE-2025-56383 itself was originally assigned a CVSS 3.1 base score of 8.4 (AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H per NVD) after a September 26, 2025 proof-of-concept release by researcher zer0t0, but the GitHub Security Advisory database rescored it to 6.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) and it is formally marked DISPUTED. The Notepad++ development team (led by Don Ho) publicly rejected the classification, calling it 'one of the most absurd entries in the National Vulnerability Database' and noting that exploitation requires an attacker already possess local write access to the Program Files installation directory (elevated privilege) or that Notepad++ be installed to a non-standard, unprivileged-writable directory — a precondition that, per the vendor, would already grant an attacker equivalent or greater capability via direct binary replacement. No official patch exists as of the reporting date; the fix track version is v8.9.7. This UAC-0099 campaign is notable precisely because it operationalizes the disputed 'non-issue' as a working in-the-wild abuse primitive against a widely deployed developer tool, and pairs it with an unrelated packaging vulnerability chain (7-Zip and WinRAR updates were also recommended, pointing to parallel abuse of archive-handling flaws in the toolchain used to unpack payloads).
Weaknesses (CWE)
CWE-427, CWE-77, CWE-506
Target sectors: government administration, defense, critical infrastructure, technology
Target regions: ukraine, Europe
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2025-56383, T1566, T1566.001, T1059.005, T1204.002, T1053.005, T1053.005, T1574.001, T1574.002, T1574.001, T1574.002