Threat Management, Threat Intelligence

Notepad++ used in new stealthy attacks targeting Ukraine

Ukraine hacked state security. Cyberattack on the financial and banking structure. Theft of secret information. On a background of a flag the binary code.

As outlined in Bleeping Computer, Ukrainian CERT has identified a new cyber campaign that leverages the legitimate Notepad++ application to distribute malware and establish persistence on victim systems. The attacks are attributed to a threat cluster known as UAC-0099, which has a history of targeting Ukrainian organizations and has been previously linked to the APT44 (Sandworm) group.

The UAC-0099 campaign employs a novel approach by distributing a ZIP archive containing Notepad++ version 8.8.3 alongside a malicious plugin named LunchPoke (NppExport.dll). This plugin is loaded by Notepad++ through its standard mechanism, allowing the attackers to create scheduled tasks and deploy further malware. The process involves a VBS script disguised as a PDF, which downloads additional archives containing the Notepad++ executable, the malicious DLL, and password-protected files. These files include components like BurnyBear, a loader for the MatchBoil V2 malware, and RemoteLibUpdater.exe, which updates command-and-control addresses and uses WinRAR to extract downloaded payloads. While the final payloads and specific targets remain undisclosed, the attackers do not exploit any vulnerabilities in Notepad++ itself. CERT-UA recommends updating Notepad++, 7-Zip, and WinRAR to their latest versions to mitigate these stealthy attacks.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds