INCIDENT EVIDENCE GRAPH
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]
- Actor: Unidentified hacking group
- Exploit: LunchPoke malicious plugin
- Method: Distributing archive with legitimate Notepad++ and malicious LunchPoke plugin disguised as a Notepad++ plugin to establish persistence