Executive Summary
In July 2026, Ukraine's CERT-UA identified a cyberattack campaign by the threat group UAC-0099, which distributed a ZIP archive containing the legitimate Notepad++ application alongside a malicious plugin named LunchPoke. This plugin established persistence on infected systems. The attackers employed a VBS script disguised as a PDF to initiate the infection chain, leading to the installation of additional malware components, including BurnyBear and MatchBoil V2 loaders. The campaign primarily targeted organizations in Ukraine and is linked to the APT44 group, also known as Sandworm. This incident underscores the evolving tactics of threat actors who exploit trusted software to deliver malware, highlighting the need for organizations to scrutinize software sources and implement robust security measures to detect and prevent such sophisticated attacks.
Why This Matters Now
The exploitation of trusted software like Notepad++ for malware delivery demonstrates the increasing sophistication of cyber threats, emphasizing the urgency for organizations to enhance their security protocols and user awareness to mitigate such risks.
Attack Path Analysis
The attack began with a phishing email containing a VBS script disguised as a PDF document, leading to the installation of a malicious Notepad++ plugin. This plugin executed a series of payloads, including LunchPoke and BurnyBear, to establish persistence and facilitate further malicious activities. The attackers leveraged these tools to escalate privileges, move laterally within the network, establish command and control channels, and potentially exfiltrate sensitive data, culminating in significant operational impact.
Kill Chain Progression
Initial Compromise
Description
Attackers sent phishing emails containing a VBS script disguised as a PDF document, which, when executed, downloaded and installed a malicious Notepad++ plugin.
Related CVEs
CVE-2025-56383
CVSS 8.4A DLL hijacking vulnerability in Notepad++ v8.8.3 allows attackers to execute arbitrary code by replacing legitimate DLL files.
Affected Products:
Notepad++ Team Notepad++ – 8.8.3
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
User Execution: Malicious File
Software Extensions
Hijack Execution Flow: DLL Side-Loading
Scheduled Task/Job: Scheduled Task
Ingress Tool Transfer
Exploitation for Client Execution
Masquerading
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: Pillar 3: Devices
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Ukrainian government agencies face targeted malware campaigns exploiting Notepad++ plugins, requiring immediate security updates and enhanced endpoint protection against nation-state actors.
Computer Software/Engineering
Software development teams using Notepad++ vulnerable to supply-chain-adjacent attacks through malicious plugins, compromising development environments and requiring secure coding tool validation.
Information Technology/IT
IT organizations face elevated risk from LunchPoke malware persistence mechanisms and scheduled task creation, necessitating enhanced monitoring and plugin security controls.
Defense/Space
Defense contractors and military organizations targeted by APT44-linked campaigns require immediate Notepad++ updates and strengthened security protocols against advanced persistent threats.
Sources
- Hackers abuse Notepad++ plugins to stealthily install malwarehttps://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/Verified
- CVE-2025-56383: Notepad++ v8.8.3 DLL Hijacking RCE Flawhttps://www.sentinelone.com/vulnerability-database/cve-2025-56383/Verified
- NVD - CVE-2025-56383https://nvd.nist.gov/vuln/detail/CVE-2025-56383Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent the initial execution of malicious scripts, it would likely limit the malware's ability to communicate with external command and control servers, reducing the attacker's control over the compromised system.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls, reducing the scope of accessible resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit lateral movement by enforcing strict segmentation policies, reducing the attacker's ability to access other systems.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit unauthorized outbound communications, reducing the attacker's ability to maintain command and control channels.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit data exfiltration by enforcing strict egress policies, reducing the attacker's ability to transfer data externally.
While Aviatrix CNSF may not prevent all operational disruptions, it would likely limit the scope of the impact by containing the attacker's activities and reducing the blast radius.
Impact at a Glance
Affected Business Functions
- Software Development
- IT Operations
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive code repositories and internal documentation.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of malware within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent malicious payloads during the initial compromise phase.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch software to mitigate vulnerabilities exploited by attackers.



