Threat IntelligenceUkraine warns of hackers hiding malware inside a fake Notepad++ plugin
CERT-UA links the campaign to UAC-0099, a group previously tied to Russia's Sandworm, which is using a genuine copy of Notepad++ to smuggle in a loader called LunchPoke.