Hackers abuse Notepad++ plugins to stealthily install malware

Summary

Attackers are distributing a malicious archive that includes the legitimate Notepad++ application along with a disguised plugin named LunchPoke. This plugin allows them to establish persistence on compromised systems, effectively hiding their malware.

IFF Assessment

FOE

This article details a new method used by hackers to distribute malware, posing a direct threat to users and their systems.

Defender Context

Defenders should be aware of this technique that abuses a popular code editor's plugin system to deliver malware. Users should exercise caution when downloading software from untrusted sources and verify the integrity of installed plugins, especially for applications like Notepad++.

Read Full Story →