CERT-UA (Ukraine’s CERT) just warned about a clear upgrade in the tactics of the Russian-linked group UAC-0099. This time, it’s not only classic phishing or script drops—the attackers are now “pretending to be useful,” steering victims into weaker points with a staged, more realistic intrusion chain. The lure: a fake-but-convincing Notepad++ “tool” setup, combined with a malicious plugin. Historically, UAC-0099 has targeted employees of overseas companies in Ukraine, deploying malware like LonePage via multiple delivery paths. Older cases also included exploiting CVE-2023-38831 in WinRAR. In the latest workflow, phishing emails often include image bait. Clicking images leads victims through link shorteners to hidden download URLs, then into a ZIP that contains a VBScript—masked using double file extensions to look like PDFs or other familiar formats. If executed, the victim hits a second stage download: Evernote.zip, containing legitimate Notepad++ 8.8.3, the malicious plugin (NppExport.dll, linked to LunchPoke), and a password-protected updater.rar for further extraction. Payloads reportedly include LunchPoke, BurnyBear, and MatchBoil v2. CERT-UA urges timely updates for WinRAR, 7-Zip, and Notepad++ to break the chain. #CyberSecurity #CERT #Phishing #Malware #UAC0099 #Ukraine
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论