The Computer Emergency Response Team of Ukraine has identified a new cyberattack campaign where Russia-aligned group UAC-0099 uses malicious Notepad++ plugins to compromise Windows systems via phishing emails.
Key Points
- The UAC-0099 threat group distributes a malicious DLL, codenamed LUNCHPOKE, disguised as a legitimate Notepad++ plugin to execute secondary payloads.
- Attacks begin with phishing emails containing image attachments that lead victims to download a ZIP archive from file-sharing services like EasySend.
- The malware chain includes the BURNYBEAR loader and a C#-based tool called MATCHBOIL.V2, which can exhaust system resources if launched incorrectly.
- CERT-UA advises organizations to update WinRAR, 7-Zip, and Notepad++ to the latest versions to mitigate risks from these exploitation techniques.
- Separate campaigns by Russian actors, including Laundry Bear and TA458, are currently targeting global webmail servers using "half-click" exploits and zero-day vulnerabilities.