As outlined in Bleeping Computer, Ukrainian CERT has identified a new cyber campaign that leverages the legitimate Notepad++ application to distribute malware and establish persistence on victim systems. The attacks are attributed to a threat cluster known as UAC-0099, which has a history of targeting Ukrainian organizations and has been previously linked to the APT44 (Sandworm) group.The UAC-0099 campaign employs a novel approach by distributing a ZIP archive containing Notepad++ version 8.8.3 alongside a malicious plugin named LunchPoke (NppExport.dll). This plugin is loaded by Notepad++ through its standard mechanism, allowing the attackers to create scheduled tasks and deploy further malware. The process involves a VBS script disguised as a PDF, which downloads additional archives containing the Notepad++ executable, the malicious DLL, and password-protected files. These files include components like BurnyBear, a loader for the MatchBoil V2 malware, and RemoteLibUpdater.exe, which updates command-and-control addresses and uses WinRAR to extract downloaded payloads. While the final payloads and specific targets remain undisclosed, the attackers do not exploit any vulnerabilities in Notepad++ itself. CERT-UA recommends updating Notepad++, 7-Zip, and WinRAR to their latest versions to mitigate these stealthy attacks.Source: Bleeping Computer
Threat Management, Threat Intelligence
Notepad++ used in new stealthy attacks targeting Ukraine

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



