Hackers abuse Notepad++ plugins to stealthily install malware
Summary
Attackers are distributing a malicious archive that includes the legitimate Notepad++ application along with a disguised plugin named LunchPoke. This plugin allows them to establish persistence on compromised systems, effectively hiding their malware.
IFF Assessment
FOE
This article details a new method used by hackers to distribute malware, posing a direct threat to users and their systems.
Defender Context
Defenders should be aware of this technique that abuses a popular code editor's plugin system to deliver malware. Users should exercise caution when downloading software from untrusted sources and verify the integrity of installed plugins, especially for applications like Notepad++.