
Phishing Email Pushes Fake Notepad++ Plugin
CERT-UA reported a real phishing campaign where victims receive an email with an image attachment that leads (via a shortened link) to a ZIP download. The ZIP…
CERT-UA reports a real phishing campaign linked to Russia-aligned actor UAC-0099 targeting Ukrainian organizations. Victims receive an email with an image attachment that leads (via a link shortener) to a file-sharing download, where a disguised script installs a trojanized Notepad++ plugin and sets up persistence. The malware chain includes a loader designed to misbehave if analysts run it incorrectly, making investigation harder.
CERT-UA linked this campaign to a Russia-aligned actor tracked as UAC-0099, targeting Ukrainian organizations, particularly in government and public sector environments. The chain begins with a phishing email carrying an image attachment. Clicking the image leads through a link shortener that redirects to a file-sharing service hosting a ZIP archive. Inside the ZIP is a VBScript file disguised as a PDF document, using a double extension and extra spaces in the filename, such as "Zavodskyi rayon.pdf .vbs", so the file appears to be a harmless document at a glance.
Once opened, the script displays a decoy PDF to keep the victim occupied while it quietly downloads a package containing a full Notepad++ installation bundled with a malicious plugin DLL. That plugin unpacks a password-protected archive using a bundled WinRAR executable and creates a scheduled task to relaunch a loader every three minutes, establishing persistence on the system.
The attack layers several deception techniques rather than relying on one trick. An image attachment feels benign, a link shortener hides the true destination, and a file named to look like a PDF exploits the common habit of trusting document extensions without checking closely. Bundling the malicious plugin with a legitimate, full copy of Notepad++ also adds a layer of camouflage, since the software looks and functions like the real tool.
Organizations should treat unexpected image-attachment emails that lead to link-shortener downloads as high risk regardless of how convincing the content looks. Staff training should specifically cover filename tricks like double extensions and excessive spacing, since these are easy to miss visually. CERT-UA also recommends keeping commonly abused tools such as WinRAR, 7-Zip, and Notepad++ updated, since attackers may exploit known vulnerabilities in these tools during later stages of an intrusion. Combining technical controls, such as blocking scheduled task creation from unusual locations, with awareness training focused on this specific delivery chain gives defenders the best chance of catching the attack before persistence is established.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It begins with a phishing email carrying an image attachment. Clicking the image opens a link shortener that redirects to a file-sharing service hosting a ZIP archive.
The ZIP contains a VBScript disguised as a PDF using a double extension and extra spaces, for example "Zavodskyi rayon.pdf .vbs", so victims believe they are opening a document.
The script opens a decoy PDF to distract the victim while downloading a package containing a full Notepad++ install plus a malicious plugin DLL that unpacks a loader and sets up a scheduled task to run it repeatedly.
The loader intentionally exhausts CPU and RAM if run without the correct arguments, which complicates sandboxing and analysis attempts.
Picture this: email hits your inbox with an innocent image attached, click it, and you’re suddenly downloading a ZIP from some EasySend-style file share. Inside that ZIP is a fake “PDF” named exactly like this: “Zavodskyi rayon.pdf .vbs”. Open it, and a decoy PDF pops up while a hidden script quietly pulls down “Evernote.zip” with Notepad++ plus a trojan plugin called NppExport.dll. That plugin, LUNCHPOKE, quietly unpacks more payloads with a bundled WinRAR, sets a scheduled task, and a loader called BURNYBEAR even hammers CPU and RAM if analysts run it wrong, this is real CERT-UA–reported tradecraft, not a toy phish. Your move: if an email image click sends you to a shortened link and then a ZIP download, stop right there and report it to security, don’t open the ZIP, don’t touch that “.pdf .vbs”.

CERT-UA reported a real phishing campaign where victims receive an email with an image attachment that leads (via a shortened link) to a ZIP download. The ZIP…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Proofpoint linked multiple real-world email campaigns to “Cruciferra,” a commercial crypter service that helps criminals hide malware from security tools. The…

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…