Hackers abuse Notepad++ plugins to stealthily install malware

Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine’s CERT has identified a campaign by UAC-0099 that distributes a ZIP archive containing legitimate Notepad++ components alongside a malicious plugin, LunchPoke, to gain persistence and deploy additional tooling. The activity uses disguised files and scheduled tasks rather than a software vulnerability or supply-chain compromise, and CERT-UA recommends updating Notepad++, 7-Zip, and WinRAR to reduce risk. #UAC-0099 #LunchPoke #Notepad++ #CERT-UA #APT44 #Sandworm

Keypoints

  • UAC-0099 is behind the attacks targeting organizations in Ukraine.
  • The campaign delivers a ZIP archive with a disguised VBS script and a fake PDF.
  • The payload includes legitimate Notepad++ files and a malicious plugin named NppExport.dll.
  • LunchPoke creates scheduled tasks and extracts further malware components from a password-protected archive.
  • CERT-UA advises updating Notepad++, 7-Zip, and WinRAR to reduce exposure.

Read More: https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/