bleeping-computer · Crawled Jul 23, 2026
Hackers abuse Notepad++ plugins to stealthily install malware
5 IoCs 2 Actors
Read original article ↗
AI Summary
Ukraine's CERT has identified a campaign by threat cluster UAC-0099 that abuses Notepad++ plugins to stealthily deploy malware. The attackers distribute a malicious archive containing a legitimate Notepad++ installation alongside a malicious plugin named NppExport.dll, which loads the LunchPoke utility to establish persistence. LunchPoke extracts and executes BurnyBear, a loader for the MatchBoil V2 malware, enabling further malicious activity including scheduled task creation and C2 communication.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 5 extracted
MITRE ATT&CK TTPs 25 techniques
T1053.005 Scheduled Task · Execution T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1204.002 Malicious File · Execution T1012 Query Registry · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol · Exfiltration T1059.003 Windows Command Shell · Execution T1069.002 Domain Groups · Discovery T1070.001 Clear Windows Event Logs · Defense Evasion T1071.004 DNS · Command And Control T1078.004 Cloud Accounts · Defense Evasion T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1090 Proxy · Command And Control T1090.002 External Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1136.002 Domain Account · Persistence T1210 Exploitation of Remote Services · Lateral Movement T1217 Browser Information Discovery · Discovery T1485 Data Destruction · Impact T1490 Inhibit System Recovery · Impact T1566 Phishing · Initial Access