bleeping-computer · Crawled Jul 23, 2026

Hackers abuse Notepad++ plugins to stealthily install malware

5 IoCs 2 Actors
Read original article ↗

AI Summary

Ukraine's CERT has identified a campaign by threat cluster UAC-0099 that abuses Notepad++ plugins to stealthily deploy malware. The attackers distribute a malicious archive containing a legitimate Notepad++ installation alongside a malicious plugin named NppExport.dll, which loads the LunchPoke utility to establish persistence. LunchPoke extracts and executes BurnyBear, a loader for the MatchBoil V2 malware, enabling further malicious activity including scheduled task creation and C2 communication.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 5 extracted

Type Value Detail
Filename NppExport.dll Details →
Filename RemoteLibUpdater.exe Details →
Filename InitTest.dll Details →
Filename updater.rar Details →
Filename Evernote.zip Details →

MITRE ATT&CK TTPs 17 techniques