bleeping-computer · Crawled Jul 23, 2026
Hackers abuse Notepad++ plugins to stealthily install malware
5 IoCs 2 Actors
Read original article ↗
AI Summary
Ukraine's CERT has identified a campaign by threat cluster UAC-0099 that abuses Notepad++ plugins to stealthily deploy malware. The attackers distribute a malicious archive containing a legitimate Notepad++ installation alongside a malicious plugin named NppExport.dll, which loads the LunchPoke utility to establish persistence. LunchPoke extracts and executes BurnyBear, a loader for the MatchBoil V2 malware, enabling further malicious activity including scheduled task creation and C2 communication.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 5 extracted
MITRE ATT&CK TTPs 17 techniques
T1053.005 Scheduled Task · Execution T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1204.002 Malicious File · Execution T1012 Query Registry · Discovery T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol · Exfiltration T1059.003 Windows Command Shell · Execution T1069.002 Domain Groups · Discovery T1070.001 Clear Windows Event Logs · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1090 Proxy · Command And Control T1129 Shared Modules · Execution T1136.002 Domain Account · Persistence T1217 Browser Information Discovery · Discovery T1566 Phishing · Initial Access