Ukraine’s cyber defense agency CERT-UA has warned that the UAC-0099 threat cluster is abusing Notepad++ to support an espionage operation against organizations in Ukraine. According to the alert, the attackers rely on the editor’s standard plugin-loading feature to make malicious activity look like a normal part of the application.
The campaign reportedly uses a legitimate copy of Notepad++ 8.8.3 bundled with a harmful plugin. By pairing real software with a malicious add-on, the attackers can turn a widely trusted text editor into a quiet malware loader while reducing suspicion around the installation.
The infection chain begins with a phishing email that includes an image and a shortened link pointing to a file-sharing service. Victims who follow the link receive a ZIP archive containing a VBScript file with a double extension, disguised to appear like a PDF document. Running that file appears to trigger the next stage of the compromise.
The warning underlines a familiar problem in modern cyberattacks: legitimate applications and expected features can be repurposed to hide malicious behavior. In this case, the use of a well-known editor, a plugin mechanism, and a phishing lure helps the operation blend into ordinary user activity and makes detection more difficult.