Global Outreach Solutions company logo — ERP, VoIP, and custom software development in PakistanGlobal Outreach
Tech Support·4 min read

Malware Threats via Notepad++ Plugins

Recent investigations by Ukraine's CERT have revealed a worrying trend in cyber attacks that exploit Notepad++ plugins to install malware. This emerging threat...

  • Security
  • Tech Support
  • Cybersecurity
  • Malware
  • Threats
  • Notepad
  • Plugins
  • Technology

By Global Outreach

Illustrated cover image for the Tech Support article "Malware Threats via Notepad++ Plugins" on Global Outreach Solutions blog

Recent investigations by Ukraine's CERT have revealed a worrying trend in cyber attacks that exploit Notepad++ plugins to install malware. This emerging threat is part of a campaign attributed to the UAC-0099 group, which primarily targets organizations in Ukraine.

The attackers are utilizing a unique strategy that involves distributing a ZIP archive containing the legitimate Notepad++ application alongside a malicious utility named LunchPoke, disguised as a plugin to maintain persistence.

Understanding the Notepad++ Attack Chain

The CERT-UA has observed a shift in the attack methods employed by UAC-0099. Recently, they have been delivering a ZIP archive that houses a VBS script masquerading as a PDF document. When executed, this PDF retrieves an additional compressed file known as Evernote.zip.

Inside this second archive, attackers include a complete version of the legitimate Notepad++ (version 8.8.3), a harmful plugin (NppExport.dll), a password-protected archive (updater.rar), and the authentic WinRAR executable.

The VBS script is responsible for installing the package into a randomly generated directory, initiating Notepad++, and subsequently loading the malicious NppExport.dll through the standard plugin-loading process.

CERT-UA explains that the DLL in question, LunchPoke, functions by creating a scheduled task on Windows. It extracts contents from the RAR file, including RemoteLibUpdater.exe and InitTest.dll.

The executable contained in the RAR file, BurnyBear, is a loader designed for the DLL file, specifically for the MatchBoil V2 malware loader. BurnyBear includes a backup mechanism to execute in case RemoteLibUpdater.exe fails, which initiates a resource exhaustion attack on the system's RAM and CPU.

This resource exhaustion attack leads to the creation of another scheduled task, updates its configuration and command-and-control (C2) address, and utilizes WinRAR to extract any downloaded malware.

While CERT-UA has not disclosed the final payloads used in the attacks or the specific objectives of the campaign, they have highlighted a significant security concern related to a DLL hijacking vulnerability (CVE-2025-56383) present in Notepad++ version 8.8.3.

Despite this, the Notepad++ team has contested the severity of this issue, arguing that the plugin loading process is a standard functionality.

To mitigate risks, CERT-UA strongly recommends that system administrators update their software: Notepad++ should be upgraded to version 8.9.7, 7-Zip to version 26.02, and WinRAR to version 7.23. These updates are crucial in closing known vulnerabilities that could be exploited by attackers.

Testing Security Layers

It's essential for security teams to recognize that a significant percentage of successful attacks—54%—go unnoticed. Alarmingly, only 14% of these incidents trigger an alert.

A breach and attack simulation, such as that outlined in the Picus whitepaper, can help test your Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems, ensuring that threats do not slip through the cracks.

Take Action Now

As the landscape of cyber threats continues to evolve, it is imperative for organizations to stay vigilant and proactive in securing their systems against such sophisticated attacks.

Related Articles

Technology teams are watching malware threats via notepad++ plugins closely because changes in this space often arrive faster than internal policies can adapt.

For product and engineering leaders, the practical question is how this could reshape roadmaps, vendor choices, and security reviews over the next few quarters.

Organizations that document lessons early tend to respond more calmly when similar patterns appear again.

In many companies, the first impact shows up in planning meetings: teams reassess priorities, revisit risk registers, and check whether existing tooling still fits.

Smaller businesses feel these shifts too. A single platform change or market move can affect customer trust, delivery timelines, and hiring plans.

The most resilient teams treat stories like this as input for quarterly reviews rather than one-day headlines.

If your business depends on modern software, ERP, VoIP, or customer-facing apps, staying informed helps you separate noise from decisions that require action.

Looking ahead, disciplined follow-through matters: assign owners, set review dates, and measure whether your response improved outcomes.

Security and compliance stakeholders should ask whether current controls still match the pace of change described in this update.

Operations leaders can reduce friction by translating the headline into a short internal brief with clear next steps for each department.

Customer support teams may see early signals through tickets, outages, or policy questions long before leadership reviews are scheduled.

Finance and procurement groups should note whether licensing, vendor risk, or implementation costs need revisiting after this development.

Training programs benefit from timely updates so staff understand what changed, what did not change, and what requires escalation.

Architecture reviews are a practical place to test assumptions, especially when new tools, platforms, or threats enter the conversation.

Documentation quality often determines how quickly a company recovers from surprises; capture decisions while context is still clear.

  • Critical wp2shell WordPress flaws exploited to install webshells
  • Australia warns of global campaign targeting vulnerable CMS platforms
  • Ukraine's army targeted in new charity-themed malware campaign
  • ShapedPlugin update flow hacked to infect WordPress sites
  • Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

Want help putting this into practice?

Global Outreach builds ERP, VoIP, and custom software for businesses in Pakistan.

Start a conversation

Related articles

← All posts