Ukraine’s CERT has identified a campaign by UAC-0099 that distributes a ZIP archive containing legitimate Notepad++ components alongside a malicious plugin, LunchPoke, to gain persistence and deploy additional tooling. The activity uses disguised files and scheduled tasks rather than a software vulnerability or supply-chain compromise, and CERT-UA recommends updating Notepad++, 7-Zip, and WinRAR to reduce risk. #UAC-0099 #LunchPoke #Notepad++ #CERT-UA #APT44 #Sandworm
Keypoints
- UAC-0099 is behind the attacks targeting organizations in Ukraine.
- The campaign delivers a ZIP archive with a disguised VBS script and a fake PDF.
- The payload includes legitimate Notepad++ files and a malicious plugin named NppExport.dll.
- LunchPoke creates scheduled tasks and extracts further malware components from a password-protected archive.
- CERT-UA advises updating Notepad++, 7-Zip, and WinRAR to reduce exposure.