Affected Systems

Organizations in Ukraine. Attack uses legitimate Notepad++ v8.8.3 bundled with malicious NppExport.dll plugin (LunchPoke), BurnyBear loader, and MatchBoil V2 malware. No vulnerability exploited; relies on social engineering and legitimate plugin-loading functionality.

Exploitation Status

Active campaign observed by Ukraine CERT-UA. Attributed to UAC-0099 threat actor, linked to APT44/Sandworm initial access operations. No vulnerability exploited; attack uses social engineering to deliver malicious archive containing legitimate software with trojanized plugin.

Business Impact

Threat actor achieves persistence via scheduled tasks and deploys multi-stage malware (LunchPoke, BurnyBear, MatchBoil V2). Final payload and campaign objectives not disclosed by CERT-UA. Organizations using Notepad++ may be targeted via phishing with VBS scripts disguised as PDF documents. Attack chain includes fallback resource exhaustion mechanism. Primary risk is to Ukrainian organizations, but technique could be adapted for broader targeting.

Urgency

đźź  Within 24 hours

Recommended Actions

  • Hunt for suspicious Notepad++ installations in non-standard directories, especially those accompanied by NppExport.dll, updater.rar, or WinRAR executables
  • Review scheduled tasks for entries created by unknown processes, particularly those launching RemoteLibUpdater.exe or similar executables from user-writable directories
  • Block execution of VBS scripts from email attachments and downloads; enforce AppLocker or similar application control policies
  • Update Notepad++ to version 8.9.7 or later, WinRAR to 7.23+, and 7-Zip to 26.02+ to mitigate known vulnerabilities in archiving tools
  • Monitor for Evernote.zip or similar archives containing full application bundles with plugins; flag anomalous plugin-loading behavior in endpoint telemetry

---

# Geopolitical Context

Geopolitical Context

Ukraine's CERT-UA has identified a campaign by threat cluster UAC-0099 distributing malicious archives containing legitimate Notepad++ software bundled with a malicious plugin (LunchPoke) to establish persistence on compromised systems. UAC-0099 has previously been assessed as providing initial access for operations conducted by APT44, a threat actor publicly attributed by multiple Western governments and cybersecurity firms to Russia's GRU Main Centre for Special Technologies (GTsST), also known as Sandworm. The campaign appears consistent with ongoing cyber operations targeting Ukrainian organizations amid the protracted Russia-Ukraine conflict. The use of multi-stage loaders (BurnyBear, MatchBoil V2) and sophisticated persistence mechanisms suggests a focus on maintaining long-term access to victim networks, likely for intelligence collection, pre-positioning for disruptive operations, or enabling follow-on attacks by more specialized threat actors.

State Actor Alignment

UAC-0099 has been previously linked by CERT-UA to providing initial access for APT44 (Sandworm), a threat actor widely attributed to Russia's GRU military intelligence service. Western governments, including the United States, United Kingdom, and European Union member states, have formally attributed Sandworm operations to Unit 74455 of the GRU and imposed sanctions on associated individuals and entities. The assessed relationship between UAC-0099 and APT44 suggests UAC-0099 may function as an access broker or initial compromise specialist within a broader Russian cyber operations ecosystem targeting Ukraine. However, CERT-UA's advisory does not explicitly attribute this specific campaign to Russian state direction, and the final payloads and operational objectives remain undisclosed.

Business Impacty pro region

This campaign underscores the persistent cyber threat environment facing Ukrainian critical infrastructure, government, and private sector organizations since Russia's 2022 full-scale invasion. The evolution of UAC-0099's tradecraft—shifting to VBS-based delivery and leveraging legitimate software bundled with malicious plugins—reflects adaptive threat actor behavior designed to evade detection by Western-supplied defensive tools and trained Ukrainian cyber defenders. For European allies providing military and cyber assistance to Ukraine, the campaign highlights the ongoing requirement for threat intelligence sharing, defensive tool provisioning, and capacity building. NATO member states with geographic proximity to Ukraine or hosting Ukrainian refugee populations may face spillover risks if compromised systems are used for lateral movement or supply chain attacks. The campaign also reinforces concerns about access brokers enabling more destructive follow-on operations, a pattern observed in previous Sandworm campaigns such as NotPetya (2017) and attacks on Ukrainian critical infrastructure.

Forecast

If UAC-0099 continues to provide initial access for APT44 or affiliated threat actors, Ukrainian organizations are likely to face follow-on operations ranging from espionage to disruptive or destructive attacks, particularly targeting critical infrastructure, defense industrial base entities, or government networks. If Western defensive assistance and threat intelligence sharing remain robust, detection and mitigation timelines may improve, potentially limiting operational impact. However, if threat actors successfully establish persistent access across multiple victim networks, the risk of coordinated, large-scale disruptive operations—timed to coincide with military or political developments—will remain elevated. European organizations with supply chain or operational links to Ukrainian entities should anticipate potential spillover risks if compromised systems are leveraged for lateral movement beyond Ukraine's borders.