UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine

UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine

First seen 24 Jul 2026, 01:15 UTC BleepingcomputerCybersecuritynewsFeeds.FeedburnerGbhackersnvd.nist.gov+1 88% similarity 77.0

Article Content

Browse articles
ThreatCluster

Ukrainian CERT has identified a cyber campaign attributed to the UAC-0099 threat cluster, which targets organizations in Ukraine using the legitimate Notepad++ application to distribute malware. The attackers deliver a ZIP archive containing Notepad++ version 8.8.3 and a malicious plugin named LunchPoke (NppExport.dll). This plugin is loaded through Notepad++'s standard mechanism, allowing the creation of scheduled tasks and deployment of further malware. The initial infection vector involves a VBS script disguised as a PDF that downloads additional archives. The campaign has been linked to the APT44 (Sandworm) group and does not exploit any vulnerabilities in Notepad++. CERT-UA recommends updating Notepad++, 7-Zip, and WinRAR to their latest versions to mitigate risks. The final payloads and specific targets of the attacks remain undisclosed.

Key Points: • UAC-0099 targets Ukrainian organizations using Notepad++ to distribute malware. • The attack involves a malicious DLL disguised as a plugin, allowing stealthy infection. • CERT-UA advises immediate updates to Notepad++ and related software to prevent exploitation.

ThreatCluster AI

Timeline

2025-09-26
CVE-2025-56383 published
A DLL hijacking vulnerability in Notepad++ v8.8.3 was disclosed, allowing malicious code execution.
nvd.nist.gov
Recent
UAC-0099 campaign identified
Ukrainian CERT reported a new cyber campaign using Notepad++ to deliver malware, attributed to UAC-0099.
Bleepingcomputer
Recent
Malware delivery method revised
UAC-0099 has changed its tactics, using a ZIP archive with Notepad++ and a malicious plugin for stealthy attacks.
Gbhackers
Recent
CERT-UA issues warning
CERT-UA has alerted organizations to update Notepad++ and related software to mitigate the new threat.
Bleepingcomputer

Community

Browse all →