Hackers abuse Notepad++ plugins to stealthily install malware
ID: 135d3ddd-cd2d-5a02-9fa5-623a8daf07a5
STIX ID: report--135d3ddd-cd2d-5a02-9fa5-623a8daf07a5
Feed Name: Bleeping Computer
Threat Score
CERT-UA reported a targeted campaign by UAC-0099 (linked to APT44/Sandworm) that distributes a ZIP containing a VBS-disguised PDF which ultimately installs a trojanized Notepad++ with a malicious plugin (LunchPoke) that creates scheduled tasks and deploys a loader (BurnyBear/MatchBoil v2); the report describes the multi-stage delivery and persistence chain, mentions a disputed DLL-hijacking CVE for Notepad++ 8.8.3, and recommends updating Notepad++, 7-Zip, and WinRAR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
