The Containment Era is here. →Explore

Executive Summary

In July 2026, Ukraine's CERT-UA identified a cyberattack campaign by the threat group UAC-0099, which distributed a ZIP archive containing the legitimate Notepad++ application alongside a malicious plugin named LunchPoke. This plugin established persistence on infected systems. The attackers employed a VBS script disguised as a PDF to initiate the infection chain, leading to the installation of additional malware components, including BurnyBear and MatchBoil V2 loaders. The campaign primarily targeted organizations in Ukraine and is linked to the APT44 group, also known as Sandworm. This incident underscores the evolving tactics of threat actors who exploit trusted software to deliver malware, highlighting the need for organizations to scrutinize software sources and implement robust security measures to detect and prevent such sophisticated attacks.

Why This Matters Now

The exploitation of trusted software like Notepad++ for malware delivery demonstrates the increasing sophistication of cyber threats, emphasizing the urgency for organizations to enhance their security protocols and user awareness to mitigate such risks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

LunchPoke is a malicious plugin disguised as a legitimate Notepad++ plugin, used by attackers to establish persistence on infected systems.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix CNSF may not prevent the initial execution of malicious scripts, it would likely limit the malware's ability to communicate with external command and control servers, reducing the attacker's control over the compromised system.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls, reducing the scope of accessible resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Aviatrix East-West Traffic Security would likely limit lateral movement by enforcing strict segmentation policies, reducing the attacker's ability to access other systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Aviatrix Multicloud Visibility & Control would likely limit unauthorized outbound communications, reducing the attacker's ability to maintain command and control channels.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit data exfiltration by enforcing strict egress policies, reducing the attacker's ability to transfer data externally.

Impact (Mitigations)

While Aviatrix CNSF may not prevent all operational disruptions, it would likely limit the scope of the impact by containing the attacker's activities and reducing the blast radius.

Impact at a Glance

Affected Business Functions

  • Software Development
  • IT Operations
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive code repositories and internal documentation.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of malware within the network.
  • Deploy Inline IPS (Suricata) to detect and prevent malicious payloads during the initial compromise phase.
  • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
  • Regularly update and patch software to mitigate vulnerabilities exploited by attackers.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image