Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Notepad++ Plugins for Silent System Breach

Hackers Exploit Notepad++ Plugins for Silent System Breach

Posted on July 23, 2026 By CWS

A recent cyber threat has emerged where hackers exploit Notepad++ plugins to infiltrate systems undetected. Identified as UAC-0099, this group has significantly advanced their tactics since mid-2026, targeting users through seemingly legitimate software.

Phishing Campaign Initiates Attack

The campaign begins with a phishing email uncovered by Ukraine’s CERT-UA. The email includes an image linking to a file-sharing service through a URL shortener, which hosts a ZIP archive named ‘Attachments to розпорядження.zip’. This archive conceals a VBS script disguised as a PDF, intended to deceive users into execution.

The script, once activated, downloads a decoy document alongside ‘Evernote.zip’, containing Notepad++ 8.8.3 and a compromised plugin folder. This carefully orchestrated setup allows attackers to gain control stealthily.

Exploit Through Notepad++ Plugins

The core of the attack lies in the ‘/plugins/NppExport/’ directory, where a malicious ‘NppExport.dll’ library replaces the legitimate plugin. The script creates a directory under %PUBLIC%, extracts the files, and launches notepad++.exe. This action loads the malicious DLL, enabling silent code execution without triggering security alerts.

This vulnerability exploits Notepad++’s plugin architecture, reminiscent of the CVE-2025-56383 DLL hijacking issue, though the Notepad++ team considers it a standard feature rather than a flaw.

Malware Components and Impact

The rogue ‘NppExport.dll’, known as LUNCHPOKE, sets the stage by creating a hidden Libraries folder and using Windows’ schtasks.exe to establish persistence. It initiates a scheduled task that executes ‘RemoteLibUpdater.exe’, identified as BURNYBEAR, every three minutes.

BURNYBEAR is tasked with loading ‘InitTest.dll’, a MATCHBOIL.V2 loader, which maintains persistence and updates configuration. It leverages WinRAR for unpacking components, fetching it from Dropbox if needed, thus escalating the threat’s complexity.

Defensive Measures and Recommendations

CERT-UA advises organizations to keep all software updated, as older versions are commonly exploited. As of July 21, 2026, secure versions include WinRAR 7.23, 7-Zip 26.02, and Notepad++ 8.9.7. Companies should scrutinize unexpected ZIP attachments and monitor for unauthorized DLLs within plugin directories.

Flagging unusual scheduled tasks can also help identify potential threats. Strengthening security measures and improving threat detection capabilities are crucial steps in mitigating these sophisticated cyber attacks.

Cyber Security News Tags:BURNYBEAR, CERT-UA, Cybersecurity, DLL hijacking, LUNCHPOKE, Malware, MATCHBOIL, Notepad, Phishing, UAC-0099, VBS script

Post navigation

Previous Post: China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks
Next Post: Russian Espionage Group Exploits Zimbra Flaw to Access Emails

Related Posts

NX Build Tool Hacked with Malware That Checks for Claude or Gemini to Find Wallets and Secrets NX Build Tool Hacked with Malware That Checks for Claude or Gemini to Find Wallets and Secrets Cyber Security News
New EDR-Freeze Tool That Puts EDRs And Antivirus Into A Coma State New EDR-Freeze Tool That Puts EDRs And Antivirus Into A Coma State Cyber Security News
Microsoft Releases Update for Windows 11, version 25H2 and 24H2 Systems Microsoft Releases Update for Windows 11, version 25H2 and 24H2 Systems Cyber Security News
Amazon Quick’s Vulnerability Exposed AI Chat to Unauthorized Users Amazon Quick’s Vulnerability Exposed AI Chat to Unauthorized Users Cyber Security News
CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure Cyber Security News
Urgent Chrome Update Fixes Critical 0-Day Vulnerability Urgent Chrome Update Fixes Critical 0-Day Vulnerability Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark