The Computer Emergency Response Team of Ukraine (CERT-UA) has issued an alert about a new cyber threat campaign involving fake Notepad++ plugins. This malicious activity is attributed to the UAC-0099 threat group, believed to be aligned with Russian interests, and employs a sophisticated method to infiltrate Windows systems.
Background of the UAC-0099 Threat Group
UAC-0099, active since mid-2022, is known for exploiting vulnerabilities in popular software like WinRAR. Previously, this group has utilized phishing emails to deploy malware strains such as LONEPAGE, MATCHBOIL, and DRAGSTARE. The current campaign represents an evolution of their tactics and continues to target users through deceptive means.
The Mechanics of the New Attack
The latest attack wave commenced with phishing emails containing image attachments. Clicking the image leads to a shortened URL, redirecting victims to a file-sharing site like EasySend[.]co. Here, a ZIP archive is downloaded, which includes a VBScript disguised as a PDF. This script further downloads a decoy PDF and an archive titled ‘Evernote.zip’, which contains several critical components.
Among these components are a genuine version of Notepad++ (8.8.3), a malicious DLL plugin (‘NppExport.dll’), a password-protected archive (‘updater.rar’), and a legitimate WinRAR executable. The VBScript’s objective is to launch Notepad++, which subsequently loads the DLL. The DLL, named LUNCHPOKE, then unpacks additional malicious files, setting up a scheduled task to perpetuate the attack.
Impact and Recommendations
The executable ‘RemoteLibUpdater.exe’, identified as BURNYBEAR, acts as a loader for ‘InitTest.dll’, a variant of MATCHBOIL now dubbed MATCHBOIL.V2. This new version can deliver further payloads, increasing the threat’s complexity. If improperly executed, it can also strain system resources, impacting performance.
To mitigate risks, CERT-UA advises organizations to update their WinRAR, 7-Zip, and Notepad++ software to the latest versions, reducing the potential for exploitation. The alert coincides with reports of a phishing campaign by a Russia-linked threat actor targeting Zimbra mail servers, further underscoring the persistent threat of cyber espionage.
Ongoing Threats and Future Outlook
The U.S. government has spotlighted a related campaign by the group known as Laundry Bear, employing innovative phishing techniques to compromise webmail services. This activity indicates a broader espionage strategy, focusing heavily on Ukrainian and Western targets.
Security firm Proofpoint has also reported continued threats from Russian actors, leveraging cross-site scripting exploits in a campaign named Operation RoundPress. These ongoing cyber threats emphasize the importance of robust security measures and remaining vigilant against evolving tactics.
As cyber threat actors persist in developing new methods of attack, staying informed and ensuring security updates are applied promptly will be critical in defending against these sophisticated campaigns.
