Hackers Bundle Notepad++ With Malware in New Campaign
UAC-0099 is using legitimate Notepad++ files alongside malicious components to target organizations in Ukraine, according to Ukraine’s Computer Emergency Response Team.
The campaign does not involve a confirmed compromise of the Notepad++ supply chain. Instead, attackers bundle the legitimate application with a malicious plugin and other files that execute during the infection process.
ZIP Archive Starts the Infection Chain
Victims receive a ZIP archive containing a Visual Basic Script disguised as a PDF document. Opening the script causes it to download another archive named Evernote.zip.
The downloaded archive contains:
- Notepad++ version 8.8.3
- A malicious Notepad++ plugin
- A password-protected RAR archive
- A copy of WinRAR
The attackers use these legitimate applications to load malware, extract additional files and make the infection appear less suspicious.
Malicious Notepad++ Plugin Loads LunchPoke
The campaign includes a malicious NppExport.dll plugin known as LunchPoke.
Notepad++ loads the DLL through its standard plugin mechanism. LunchPoke then creates a scheduled task to maintain persistence on the compromised Windows system.
The plugin also extracts two additional files named RemoteLibUpdater.exe and InitTest.dll.
BurnyBear Loads MatchBoil V2
CERT-UA identified RemoteLibUpdater.exe as BurnyBear. The malware loads MatchBoil V2, another loader used to continue the attack.
MatchBoil creates an additional scheduled task and updates its configuration, including the command-and-control server address.
It also uses WinRAR to extract further payloads from the password-protected archive included in Evernote.zip.
Fallback Can Consume CPU and RAM
BurnyBear includes a fallback mechanism that activates when RemoteLibUpdater.exe fails to launch correctly.
CERT-UA warned that this fallback behavior can cause heavy CPU and RAM consumption on the infected computer. The activity could affect system performance and help administrators notice the compromise.
Final Malware Remains Unknown
CERT-UA did not disclose the final malware payload delivered during the observed attacks.
The agency also did not reveal the names of the affected organizations or provide details about the attackers’ intended objectives.
UAC-0099 primarily targets Ukrainian organizations and has previously used malicious scripts, legitimate software and multi-stage malware loaders in its operations.
CERT-UA Recommends Software Updates
CERT-UA recommends updating Notepad++ to version 8.9.7.
Administrators should also install 7-Zip version 26.02 and WinRAR version 7.23 or later. Keeping these applications updated can reduce exposure to known vulnerabilities and techniques that attackers may use to hide malicious activity.
In other security news, the FakeAgent campaign used Bing ads to distribute SectopRAT, while an Adobe Acrobat extension vulnerability could allow attackers to read WhatsApp Web chats.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages