File UAC-0099: Campaign uses fake Notepad++ plugin to install LunchPoke malware

The new campaign discovered by CERT-UA shows a familiar but still highly effective attack path: bundling legitimate software with a malicious component, then abusing the normal plugin-loading mechanism to maintain persistence on the victim machine. According to BleepingComputer, the UAC-0099 threat cluster is distributing a package that contains a legitimate copy of Notepad++ together with the malicious LunchPoke utility disguised as a plugin to establish persistence on Windows.

The notable point is that the campaign does not rely on directly exploiting a Notepad++ vulnerability or a supply chain incident in the software project. Instead, the attackers abuse user trust in a familiar application, combining a lure script, multi-layer archives, and a malicious DLL to bring the loader into the system.

Sơ đồ chuỗi tấn công UAC-0099 dùng Notepad++ và plugin độc hại

Who is UAC-0099 and why does this campaign matter?

UAC-0099 is a threat cluster observed primarily targeting organizations in Ukraine. The group has previously been linked to providing initial access for APT44 operations, more widely known as Sandworm. That makes any shift in UAC-0099 delivery techniques significant for defenders, especially in environments with high geopolitical risk.

In this campaign, the infection chain begins with a VBS file disguised as a PDF document. When the user runs it, the script downloads another archive named Evernote.zip. Inside that package are a legitimate Notepad++ version 8.8.3, a malicious DLL named NppExport.dll, a legitimate copy of WinRAR, and a password-protected archive.

A multi-stage attack chain

After being deployed into a random directory, Notepad++ is launched to load the malicious DLL through the plugin mechanism. CERT-UA identifies this DLL as LunchPoke, which is responsible for creating a scheduled task on Windows and extracting the next components from the RAR archive.

The following components include RemoteLibUpdater.exe and InitTest.dll. Citing CERT-UA analysis, BleepingComputer reports that RemoteLibUpdater.exe is BurnyBear, a loader used to load MatchBoil V2. BurnyBear also has a fallback mechanism: if it cannot launch the main component, it can trigger behavior that exhausts the victim machine's RAM and CPU resources.

At the next stage, the malware continues creating scheduled tasks, updating configuration and command-and-control server addresses, then using WinRAR to extract downloaded programs. CERT-UA has not clearly disclosed the final payload in the observed samples, nor has it provided a specific list of targeted organizations.

Not every risk starts with a zero-day

This case is an important reminder that endpoint defense cannot rely only on lists of known vulnerabilities. A legitimate application, a legitimate compression tool, and a legitimate plugin mechanism can still become cover for malware if the initial execution flow is not controlled.

BleepingComputer also notes that CERT-UA mentioned CVE-2025-56383, a DLL hijacking issue related to Notepad++ 8.8.3, while the Notepad++ team has argued that plugin loading is standard functionality. Even if classification differs, the practical recommendation remains clear: organizations need to control software sources, monitor unusual DLLs in application directories, and track newly created scheduled tasks.

Lessons for organizations and users

For everyday users, the biggest risk lies in opening files disguised as documents and running scripts from unverified sources. For enterprises, priorities should include blocking unnecessary script execution, limiting write permissions in application directories, controlling third-party plugins, and monitoring processes such as WinRAR or text editors when they unexpectedly participate in a code-download chain.

CERT-UA recommends that administrators update Notepad++ to version 8.9.7, 7-Zip to 26.02, and WinRAR to 7.23 to reduce exposure to known weaknesses. Beyond patching, security teams should add hunting queries for unfamiliar NppExport.dll files, scheduled tasks created from random directories, VBS processes launching editors, and archive-extraction activity that does not match normal user behavior.

The UAC-0099 campaign shows that modern attack techniques do not always need to be highly complex to be effective. When legitimate software is used as cover, the difference lies in detecting abnormal context: who launched it, from where, what it downloaded, and why an office tool is creating persistence on the system.

VNCyberS compiled from BleepingComputer and CERT-UA

Contact Us

Email: [email protected]
Phone: +84 903260277