logo

Hackers Abuse Notepad++ Plugins to Compromise Your System Silently

ID: 7b1caf1c-9645-5929-838f-f372027ff6c7

STIX ID: report--7b1caf1c-9645-5929-838f-f372027ff6c7

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Guru Baran

...
...

CERT-UA uncovered an active UAC-0099 campaign that uses phishing and a trojanized Notepad++ plugin (NppExport.dll, tracked as LUNCHPOKE) to achieve silent code execution, install a loader (BURNYBEAR / RemoteLibUpdater.exe) and a MATCHBOIL.V2 loader (InitTest.dll) that provides persistence and payload delivery; defenders are advised to inspect plugin directories, flag unusual scheduled tasks, and ensure software like Notepad++, WinRAR, and 7-Zip are up to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.