Cybersecurity Threat Advisory: Malicious Notepad++ plugins

Cybersecurity Threat Advisory

Cybersecurity Threat AdvisoryCERT-UA has identified an ongoing campaign in which threat group UAC-0099 distributes trojanized Notepad++ bundles that install malware on Windows systems. The campaign primarily targets organizations in Ukraine and is linked to activity associated with APT44 (Sandworm).

What is the threat?

The threat cluster UAC-0099 distributes archives that include a legitimate copy of Notepad++ alongside a malicious plugin DLL masquerading as a standard Notepad++ component. Once launched, the editor’s normal plugin-loading mechanism executes the malicious DLL to establish persistence, deploy additional loaders, and enable follow-on payload delivery.

Attackers distribute ZIP archives containing:

  • A script disguised as a PDF document.
  • A legitimate copy of Notepad++.
  • A malicious plugin DLL (NppExport.dll).
  • Additional malware components and tools.

The malware then establishes persistence, deploys additional payloads, and updates command-and-control (C2) settings to support further compromise. Researchers have found no evidence that attackers compromised the official Notepad++ project or plugin repository.

Why is it noteworthy?

This campaign abuses the trusted plugin-loading behavior of a legitimate application instead of exploiting a software vulnerability. By bundling a legitimate copy of Notepad++ with a malicious plugin, attackers increase user trust and reduce the likelihood of detection. The activity is also linked to UAC-0099, a threat group known for providing initial access for more advanced attacks.

What is the exposure or risk?

Organizations face increased risk when users:

  • Run scripts delivered through email or downloads.
  • Install software from untrusted archives.
  • Use older or unmanaged software installations.

Successful compromise can lead to:

  • Persistent access.
  • Additional malware deployment.
  • Credential theft.
  • Lateral movement.
  • Data exfiltration.
  • Operational disruption.

What are the recommendations?

Barracuda recommends the following actions:

Software hygiene and patching

  • Update Notepad++ to version 8.9.7 or later.
  • Update 7-Zip and WinRAR to current versions.
  • Remove outdated or duplicate Notepad++ installations.

Control plugin and script execution

  • Install Notepad++ only from official sources.
  • Block unauthorized DLL plugins.
  • Restrict or disable Windows Script Host (WSH) where possible.
  • Block script execution from email attachments and web downloads.
  • Enable endpoint protections that monitor scripting activity and DLL loading.

Hunting and detection

  • Search for unexpected Notepad++ installations.
  • Investigate suspicious files such as Evernote.zip, updater.rar, RemoteLibUpdater.exe, and InitTest.dll.
  • Review newly created scheduled tasks.
  • Monitor for unusual child processes or network activity originating from Notepad++.

References

For more in-depth information about the recommendations, please visit the following links:

If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.

This post originally appeared on Smarter MSP.