● News

Threat Actors Exploit Notepad++ Plugins to Deploy Malware on Windows

July 24, 2026 · snewle
Threat Actors Exploit Notepad++ Plugins to Deploy Malware on Windows

A threat cluster designated as UAC-0099 has developed a new malware delivery technique that weaponizes Notepad++ plugins to infect Windows systems, according to a warning issued by CERT-UA. The campaign leverages the popular text editor application to load malicious DLL files disguised as legitimate plugins, marking a shift in the threat actor’s attack methodology.

How Does the Notepad++ Attack Method Work?

The threat actors behind this campaign exploit the legitimate Notepad++ application as a vehicle for malware deployment. By disguising malicious DLL files as authentic plugins, the attackers can silently compromise Windows systems when users launch the application. This technique abuses the trusted nature of Notepad++ to bypass security measures that might otherwise flag suspicious executable files.

What Malware Tools Are Being Deployed?

CERT-UA has identified multiple malware tools being distributed through this campaign. Two newly discovered tools, designated LUNCHPOKE and BURNYBEAR, have been observed in attacks that began in mid-summer 2026. Additionally, the threat cluster is utilizing an updated version of a previously known loader called MATCHBOIL.V2. These tools represent an evolution in the UAC-0099 group’s capabilities and demonstrate their continued development of malware arsenals.

When Did This Campaign Begin?

The malicious activity involving weaponized Notepad++ plugins has been ongoing since mid-summer 2026, according to CERT-UA’s observations. This timeline indicates that the threat actors have been actively exploiting this technique for several months, potentially compromising numerous systems during this period.

What Makes This Threat Significant?

The campaign’s significance lies in its abuse of a widely trusted application used by developers, security professionals, and general users worldwide. By compromising Notepad++, a legitimate tool frequently used in technical environments, the attackers can potentially gain access to sensitive development environments and systems that might contain valuable data or access credentials. The use of DLL sideloading through plugins represents a stealthy approach that can evade traditional security controls.

Organizations and individuals who use Notepad++ should remain vigilant about the source of any plugins they install and monitor their systems for unexpected DLL files or suspicious plugin behavior. Security teams should consider implementing additional monitoring for Notepad++ processes and reviewing installed plugins for legitimacy.

Source: GBHackers Security