← Back to news

UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations

Security Affairs24/07/2026, 09:54
Read full article →

Summary

AI-Generated

Key Points:

  • UAC-0099, a Russia-aligned threat actor, is delivering malware via a fake Notepad++ plugin after phishing, using a sophisticated loader that sabotages itself if run incorrectly.
  • The attack targets Ukrainian organizations, leveraging a trojanized Notepad++ plugin to execute malicious payloads while remaining undetected by the victim.
  • Recommended actions include updating WinRAR, 7-Zip, and Notepad++ to their latest versions to mitigate exploitation risks and treating unexpected emails with image attachments as high-risk.

Technical Details: The malware delivery involves a phishing email leading to a ZIP archive containing a VBScript that downloads and executes a malicious DLL (NppExport.dll) alongside legitimate software. This DLL creates scheduled tasks to maintain persistence and execute further payloads.

MITRE ATT&CK Techniques:

  • T1566 - Phishing (Initial Access)
  • T1203 - User Execution (Execution)
  • T1053.005 - Scheduled Task/Job: Scheduled Task (Persistence)
  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.