Ukraine says UAC-0099 is abusing Notepad++ plugin loading to install LunchPoke and BurnyBear malware

Ukraine’s cyber defenders say a threat group linked to earlier Sandworm initial-access activity is disguising malware as a Notepad++ plugin to infect organizations in Ukraine. CERT-UA says UAC-0099 delivers a VBS script disguised as a PDF, which fetches a ZIP containing legitimate Notepad++ 8.8.3 plus a malicious NppExport.dll that installs LunchPoke persistence, then extracts BurnyBear and the MatchBoil V2 loader. CERT-UA also referenced disputed Notepad++ issue CVE-2025-56383 and urged updates to Notepad++ 8.9.7, 7-Zip 26.02, and WinRAR 7.23.
Why it matters: This is a stealthy malware delivery technique that hides inside normal application behavior, making it relevant to defenders and users in Ukraine now. Organizations should review Notepad++ plugin use, hunt for the named files and scheduled tasks, and update the listed software promptly.

Sources

Hackers abuse Notepad++ plugins to stealthily install malware
Bill Toulas 2026.07.23 100% relevant
This article establishes a distinct campaign by UAC-0099 using Notepad++ plugin loading and specific malware families (LunchPoke, BurnyBear, MatchBoil V2), which is not the same underlying event as any currently tracked story.
← Back to all stories