Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Notepad++ used in new stealthy attacks targeting Ukraine

A new campaign attributed to UAC-0099 distributes Notepad++ 8.8.3 alongside a malicious plugin (LunchPoke/NppExport.dll) via a ZIP archive, using the application's standard plugin mechanism to establish persistence and deploy further malware. The attack chain involves a VBS script disguised as a PDF that downloads additional components, including loaders like BurnyBear and RemoteLibUpdater.exe. No vulnerability in Notepad++ is exploited; mitigation involves updating Notepad++, 7-Zip, and WinRAR to their latest versions.
Read Full Article →

Threat Management , Threat Intelligence Notepad++ used in new stealthy attacks targeting Ukraine July 23, 2026 Share By SC Staff (Adobe Stock) As outlined in Bleeping Computer, Ukrainian CERT has identified a new cyber campaign that leverages the legitimate Notepad++ application to distribute malware and establish persistence on victim systems. The attacks are attributed to a threat cluster known as UAC-0099, which has a history of targeting Ukrainian organizations and has been previously linked to the APT44 (Sandworm) group. The UAC-0099 campaign employs a novel approach by distributing a ZIP archive containing Notepad++ version 8.8.3 alongside a malicious plugin named LunchPoke (NppExport.dll). This plugin is loaded by Notepad++ through its standard mechanism, allowing the attackers to create scheduled tasks and deploy further malware. The process involves a VBS script disguised as a PDF, which downloads additional archives containing the Notepad++ executable, the malicious DLL, and password-protected files. These files include components like BurnyBear, a loader for the MatchBoil V2 malware, and RemoteLibUpdater.exe, which updates command-and-control addresses and uses WinRAR to extract downloaded payloads. While the final payloads and specific targets remain undisclosed, the attackers do not exploit any vulnerabilities in Notepad++ itself. CERT-UA recommends updating Notepad++, 7-Zip, and WinRAR to their latest versions to mitigate these stealthy attacks. Source: Bleeping Computer SC Staff Related Endpoint/Device Security Lampion banking malware continues to target Portuguese organizations SC Staff July 23, 2026 A banking Trojan known as Lampion, believed to have originated in Brazil, is still actively used in ongoing attacks targeting Portuguese organizations. EDR Indicators of Compromise (IOCs) vs Indicators of Attack (IOAs) SC Media Editorial Intelligence, reviewed by Jason Colby July 23, 2026 Each signal type drives different control decisions EDR Nation-State Threat Actors Explained SC Media Editorial Intelligence, reviewed by Jason Colby July 23, 2026 Understanding what defines a nation-state actor — and what does not — changes how defenders evaluate threat intelligence relevance Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Cybercast RSAC Preview: Exposure management takes center stage On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor Deauthentication Attack Denial of Service Dictionary Attack Distributed Scans Google Hacking Hybrid Attack Information Warfare Reconnaissance You can skip this ad in 5 seconds

Share this article