CERT-UA update advice for Notepad++, 7-Zip, and WinRAR
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CERT-UA told administrators to update Notepad++, 7-Zip, and WinRAR after attackers abused the software in a stealthy delivery chain. The guidance targets known flaws and reduces the risk of malicious plugin loading and related abuse in affected environments. The advisory is tied to a live attack pattern against systems used by organizations in Ukraine.
Related Happenings
UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine
Campaign
H score33
First: 23.07.2026 19:32
Last: 23.07.2026 19:32
Sources 1
How related:
The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm.
About this happening:
The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in...
UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine
CampaignHow related: The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm.
About this happening: The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in...
Turla STOCKSTAY .NET backdoor deployment
Malware Activity
H score27
First: 26.06.2026 10:15
Last: 26.06.2026 10:15
Sources 1
About this happening:
Turla's STOCKSTAY backdoor has been newly detailed as a .NET espionage implant used against government and military organizations in Ukraine and entities linked to I...
Turla STOCKSTAY .NET backdoor deployment
Malware ActivityAbout this happening: Turla's STOCKSTAY backdoor has been newly detailed as a .NET espionage implant used against government and military organizations in Ukraine and entities linked to I...
Turla STOCKSTAY phishing campaign targeting Ukraine and Europe
Campaign
H score37
First: 26.06.2026 10:15
Last: 26.06.2026 10:15
Sources 1
About this happening:
Turla's STOCKSTAY phishing campaign is targeting government and military organizations in Ukraine and selected European entities, extending a recurring espionage opera...
Turla STOCKSTAY phishing campaign targeting Ukraine and Europe
CampaignAbout this happening: Turla's STOCKSTAY phishing campaign is targeting government and military organizations in Ukraine and selected European entities, extending a recurring espionage opera...
AGEWHEEZE remote access trojan activity
Malware Activity
H score43
First: 01.04.2026 19:10
Last: 01.04.2026 19:10
Sources 1
About this happening:
CERT-UA disclosed AGEWHEEZE, a remote access trojan delivered through a password-protected ZIP that enabled remote control over infected devices. The malware was sprea...
AGEWHEEZE remote access trojan activity
Malware ActivityAbout this happening: CERT-UA disclosed AGEWHEEZE, a remote access trojan delivered through a password-protected ZIP that enabled remote control over infected devices. The malware was sprea...
Notepad++ hit by network compromise
Incident
H score17
First: 03.02.2026 06:55
Last: 03.02.2026 06:55
Sources 1
About this happening:
The Notepad++ hosting breach enabled attackers to hijack the software update path and selectively redirect some users to malicious servers, creating a supply-chain ris...
Notepad++ hit by network compromise
IncidentAbout this happening: The Notepad++ hosting breach enabled attackers to hijack the software update path and selectively redirect some users to malicious servers, creating a supply-chain ris...
Latest development: 18.02.2026 09:40
Notepad++ released version 8.9.2 to harden the update mechanism after the hijacked update path was used to deliver targeted malware. The release adds a "double lock" design with verification of the signed installer downloaded from GitHub and verification of the signed XML returned by the update server at notepad-plus-plus[.]org, and it also introduces WinGUp hardening including removal of libcurl.dll, removal of CURLSSLOPT_ALLOW_BEAST and CURLSSLOPT_NO_REVOKE, and restriction of plugin management execution to programs signed with the same certificate as WinGUp.
Timeline
-
23.07.2026 19:32 2 articles · 1h ago
CERT-UA urges updates to Notepad++, 7-Zip, and WinRAR
Mitigation Patch UpdateCERT-UA advised system administrators to update Notepad++ to version 8.9.7, 7-Zip to version 26.02, and WinRAR to version 7.23 after UAC-0099 used a ZIP/VBS delivery chain with a disguised PDF, a malicious Notepad++ plugin, and related loaders to enable stealthy attacks.
Show sources
- Hackers abuse Notepad++ plugins to stealthily install malware — www.bleepingcomputer.com — 23.07.2026 19:32
- Hackers abuse Notepad++ plugins to stealthily install malware — www.bleepingcomputer.com — 23.07.2026 19:32