Hackers Use Notepad++ Plugin to Stealthily Deploy Malware

Ukraine's CERT warns of a new attack using a fake Notepad++ plugin (LunchPoke) to stealthily install malware. Learn how to protect your system.

viernes, 24 de julio de 2026 • 4 min read • Q2BSTUDIO Team

El falso plugin LunchPoke permite infecciones persistentes

The recent discovery by Ukraine's CERT has put the cybersecurity community on alert: an active campaign is using compressed archives that contain a legitimate copy of Notepad++ along with a malicious utility called LunchPoke, which disguises itself as a plugin of the popular text editor. The technique, seemingly simple, reveals a worrying sophistication: attackers not only manage to run the legitimate software normally but also establish a persistence mechanism that enables remote access and information theft silently. This type of threat, which abuses the trust users place in widely used applications, demands a deep analysis of software supply chain vulnerabilities and the measures companies must adopt to protect themselves.

Notepad++ is an open-source tool highly popular among developers and system administrators. Its plugin system, managed through the Plugin Manager, allows third parties to extend functionalities. However, this very openness becomes an attack vector when cybercriminals distribute their own malicious 'extensions.' In the discovered case, the compressed archive includes the original Notepad++ installer and a fake plugin that, when loaded, executes LunchPoke. Once inside the system, this malware modifies registry keys, startup programs, or scheduled tasks to ensure it re-executes after every reboot. Persistence is key: the attacker ensures that even if the user closes Notepad++, the malware remains active in the background.

The campaign, according to the Ukrainian CERT, appears to target mainly government entities and companies in critical sectors, although the method could easily be replicated against any organization. Using legitimate software as a decoy reduces suspicion: security teams usually focus on detecting unknown executable files, but a signed or known-hash Notepad++ installer goes unnoticed. Moreover, loading plugins often does not trigger alerts in many antivirus programs, since the main process (notepad++.exe) is trusted. This living off the land strategy leverages native or legitimate tools to hide malicious activities, greatly complicating traditional detection.

From a business perspective, an attack of this kind can have devastating consequences. LunchPoke, although described as a 'persistence utility,' typically deploys additional payloads: keyloggers, screen capture tools, ransomware, or backdoors for data exfiltration. The loss of sensitive information, operational disruption, or credential compromise are just a few of the threats. Furthermore, the malware's execution within the context of a known application hinders forensic investigation and allows the attacker to move laterally within the network undetected for weeks or months.

To mitigate these risks, organizations need a comprehensive cybersecurity approach combining technology, processes, and people. It is not enough to install an antivirus; continuous monitoring of anomalous behaviors, network segmentation, application allowlisting, and especially employee training to avoid opening suspicious files or installing plugins from unverified sources are required. This is where having a technology partner that offers advanced cybersecurity services, such as penetration testing and security audits that identify similar attack vectors before they are exploited, becomes crucial.

Q2BSTudio, a company specialized in software development and technology, understands that security is not an add-on but a fundamental pillar in any digital project. Therefore, it integrates Secure Software Development Lifecycle (SSDLC) principles from the design phase and offers custom software solutions that include robust security controls, as well as cloud architectures (AWS and Azure) incorporating firewalls, intrusion detection, and continuous monitoring. Additionally, its artificial intelligence experts develop AI agents capable of analyzing large volumes of logs and detecting suspicious behavior in real time, a key capability against threats like LunchPoke that try to remain unnoticed.

In the realm of visibility and incident response, Business Intelligence (BI) solutions such as Power BI play a crucial role. Q2BSTudio helps companies implement cybersecurity dashboards that consolidate data from multiple sources (antivirus, firewalls, endpoint detection systems) and generate early warnings. They also offer security orchestration, automation, and response (SOAR) processes that can automatically isolate an infected machine before the malware spreads. All this, combined with continuous training and periodic risk assessments, builds a layered defense against attacks that abuse trust in tools like Notepad++.

The lesson from this campaign is clear: no software, no matter how well-known, is exempt from being used as an attack vector. The supply chain of plugins, extensions, and add-ons is a blind spot that cybercriminals exploit with increasing frequency. Companies must adopt strict software approval policies, keep their behavior-based detection systems updated, and have a prepared incident response team. In this context, partnering with experts like Q2BSTudio not only provides technical solutions but also a strategic vision to anticipate threats, embed cybersecurity into organizational culture, and protect the most valuable asset: data.

In summary, the abuse of Notepad++ plugins to install malware like LunchPoke represents an evolution in attacker tactics, aiming to go unnoticed by leveraging legitimate tools. To counter this, organizations need a technology partner offering cybersecurity services, custom application development with integrated security controls, robust cloud solutions (AWS/Azure), artificial intelligence for early detection, and business intelligence for monitoring. Q2BSTudio is prepared to face these challenges, providing clients with the peace of mind that their infrastructure is protected against emerging threats. Prevention, constant monitoring, and training are the keys to preventing a simple malicious plugin from turning into a critical security breach.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.