Feeds.Feedburner
UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Ukrainian CERT has identified a cyber campaign attributed to the UAC-0099 threat cluster, which targets organizations in Ukraine using the legitimate Notepad++ application to distribute malware. The attackers deliver a ZIP archive containing Notepad++ version 8.8.3 and a malicious plugin named LunchPoke (NppExport.dll). This plugin is loaded through Notepad++'s standard mechanism, allowing the creation of scheduled tasks and deployment of further malware. The initial infection vector involves a VBS script disguised as a PDF that downloads additional archives. The campaign has been linked to the APT44 (Sandworm) group and does not exploit any vulnerabilities in Notepad++. CERT-UA recommends updating Notepad++, 7-Zip, and WinRAR to their latest versions to mitigate risks. The final payloads and specific targets of the attacks remain undisclosed.
Key Points: • UAC-0099 targets Ukrainian organizations using Notepad++ to distribute malware. • The attack involves a malicious DLL disguised as a plugin, allowing stealthy infection. • CERT-UA advises immediate updates to Notepad++ and related software to prevent exploitation.