Hackers Abuse Notepad++ Plugins to Compromise Your System Silently
ID: 7b1caf1c-9645-5929-838f-f372027ff6c7
STIX ID: report--7b1caf1c-9645-5929-838f-f372027ff6c7
Feed Name: cybersecurityNews.com
Threat Score
CERT-UA uncovered an active UAC-0099 campaign that uses phishing and a trojanized Notepad++ plugin (NppExport.dll, tracked as LUNCHPOKE) to achieve silent code execution, install a loader (BURNYBEAR / RemoteLibUpdater.exe) and a MATCHBOIL.V2 loader (InitTest.dll) that provides persistence and payload delivery; defenders are advised to inspect plugin directories, flag unusual scheduled tasks, and ensure software like Notepad++, WinRAR, and 7-Zip are up to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
