UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
ID: 7ed0c1bb-94f6-582a-9deb-18693d376301
STIX ID: report--7ed0c1bb-94f6-582a-9deb-18693d376301
Feed Name: ThreatCluster
Threat Score
CERT-UA reports an active campaign by UAC-0099 (linked to APT44/Sandworm) that distributes a malicious Notepad++ plugin (LunchPoke / NppExport.dll) inside ZIP archives; initial access is via a VBS script masquerading as a PDF which downloads additional archives, enabling scheduled tasks and follow-on malware. Organizations in Ukraine are targeted and CERT-UA advises updating Notepad++, 7-Zip, and WinRAR; final payloads and specific targets remain undisclosed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
