Feeds.Feedburner
Malware Campaign Exploits Notepad++ Plugins to Target Ukrainian Organizations
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Ukrainian CERT has reported a cyber campaign attributed to threat cluster UAC-0099, targeting organizations in Ukraine. The attackers distribute a ZIP archive containing Notepad++ version 8.8.3 and a malicious plugin called LunchPoke (NppExport.dll). This plugin is loaded through Notepad++'s standard mechanism, allowing the creation of scheduled tasks and further malware deployment. The attack vector involves a VBS script disguised as a PDF, which downloads additional malicious files. Notably, the attackers do not exploit any vulnerabilities in Notepad++. CERT-UA recommends updating Notepad++, 7-Zip, and WinRAR to their latest versions to mitigate these attacks. The specific targets and final payloads of the campaign remain undisclosed.
Key Points: • UAC-0099 targets Ukrainian organizations using Notepad++ for malware distribution. • The attack involves a VBS script disguised as a PDF to deliver malicious files. • CERT-UA advises immediate updates to Notepad++ and other software to prevent exploitation.