CVE Tools
Back to feed
Exploited in the wild Notepad++ UAC-0099 malware WinRAR APT44

Hackers abuse Notepad++ plugins to stealthily install malware

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Researchers have identified a new cyberattack method where threat actors disguise malware as Notepad++ plugins to silently install malicious tools on victims' systems. The campaign, attributed to UAC-0099, involves delivering a ZIP file containing a legitimate version of Notepad++ alongside a harmful plugin called NppExport.dll. This plugin, known as LunchPoke, establishes persistence by creating scheduled tasks and downloading additional payloads like BurnyBear and MatchBoil V2. The attack leverages a reported vulnerability (CVE-2025-56383), though the Notepad++ team disputes its classification as a flaw. Security experts recommend updating Notepad++ to version 8.9.7 and WinRAR to 7.23 to mitigate risks.