Summary
Key Points:
- UAC-0099, a Russia-aligned threat actor, is delivering malware via a fake Notepad++ plugin after phishing, using a sophisticated loader that sabotages itself if run incorrectly.
- The attack targets Ukrainian organizations, leveraging a trojanized Notepad++ plugin to execute malicious payloads while remaining undetected by the victim.
- Recommended actions include updating WinRAR, 7-Zip, and Notepad++ to their latest versions to mitigate exploitation risks and treating unexpected emails with image attachments as high-risk.
Technical Details: The malware delivery involves a phishing email leading to a ZIP archive containing a VBScript that downloads and executes a malicious DLL (NppExport.dll) alongside legitimate software. This DLL creates scheduled tasks to maintain persistence and execute further payloads.
MITRE ATT&CK Techniques:
- T1566 - Phishing (Initial Access)
- T1203 - User Execution (Execution)
- T1053.005 - Scheduled Task/Job: Scheduled Task (Persistence)
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
IOCs Mentioned: None mentioned
Join the discussion — sign up to comment, upvote, and save articles.