logo

UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine

ID: 7ed0c1bb-94f6-582a-9deb-18693d376301

STIX ID: report--7ed0c1bb-94f6-582a-9deb-18693d376301

Feed Name: ThreatCluster

Threat Score
82/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

...
...

CERT-UA reports an active campaign by UAC-0099 (linked to APT44/Sandworm) that distributes a malicious Notepad++ plugin (LunchPoke / NppExport.dll) inside ZIP archives; initial access is via a VBS script masquerading as a PDF which downloads additional archives, enabling scheduled tasks and follow-on malware. Organizations in Ukraine are targeted and CERT-UA advises updating Notepad++, 7-Zip, and WinRAR; final payloads and specific targets remain undisclosed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.