Malware Campaign Exploits Notepad++ Plugins to Target Ukrainian Organizations

Malware Campaign Exploits Notepad++ Plugins to Target Ukrainian Organizations

First seen 24 Jul 2026, 01:15 UTC BleepingcomputerFeeds.Feedburnernvd.nist.gov 92% similarity 63.9

Article Content

Browse articles
ThreatCluster

Ukrainian CERT has reported a cyber campaign attributed to threat cluster UAC-0099, targeting organizations in Ukraine. The attackers distribute a ZIP archive containing Notepad++ version 8.8.3 and a malicious plugin called LunchPoke (NppExport.dll). This plugin is loaded through Notepad++'s standard mechanism, allowing the creation of scheduled tasks and further malware deployment. The attack vector involves a VBS script disguised as a PDF, which downloads additional malicious files. Notably, the attackers do not exploit any vulnerabilities in Notepad++. CERT-UA recommends updating Notepad++, 7-Zip, and WinRAR to their latest versions to mitigate these attacks. The specific targets and final payloads of the campaign remain undisclosed.

Key Points: • UAC-0099 targets Ukrainian organizations using Notepad++ for malware distribution. • The attack involves a VBS script disguised as a PDF to deliver malicious files. • CERT-UA advises immediate updates to Notepad++ and other software to prevent exploitation.

ThreatCluster AI

Timeline

2025-09-26
CVE-2025-56383 published
A DLL hijacking flaw in Notepad++ v8.8.3 was published, but the Notepad++ team disputed the issue.
BleepingComputer
2026-07-23
Cyber campaign identified by Ukrainian CERT
CERT-UA reported a campaign using Notepad++ to stealthily install malware targeting Ukrainian organizations.
BleepingComputer
2026-07-23
Malicious plugin LunchPoke discovered
The campaign utilizes a malicious plugin (NppExport.dll) to establish persistence on victim systems.
Feeds.Feedburner

Community

Browse all →