LUNCHPOKE is a Windows malware component used by the UAC-0099 threat cluster as part of a multi-stage intrusion chain targeting organizations in Ukraine. It is deployed by abusing the normal plugin-loading behavior of a bundled legitimate Notepad++ installation, where a trojanized plugin DLL is loaded when the application starts. The broader delivery chain uses phishing to distribute an archive containing a disguised script, which retrieves the packaged application and malware components.
Once executed, LUNCHPOKE creates a hidden working directory, extracts a password-protected archive containing follow-on components, and establishes persistence through a scheduled task configured to relaunch the next-stage executable at frequent intervals. It also copies a legitimate Windows utility to help disguise persistence setup activity. The extracted follow-on payloads include BURNYBEAR and an updated MATCHBOIL.V2 loader. In this role, LUNCHPOKE functions as an installation and persistence component that prepares the host for continued execution of downstream malware.
The malware has been associated with campaigns attributed to UAC-0099, a cluster previously linked to providing initial access for operations conducted by APT44 (Sandworm). Observed tradecraft emphasizes stealth through use of legitimate software, DLL sideload-style plugin abuse, scheduled-task persistence, and staged deployment of additional payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malicious “NppExport.dll” is tracked as LUNCHPOKE, a tool that builds a hidden Libraries folder, extracts a password-protected “updater.rar” containing “RemoteLibUpdater.exe” and “InitTest.dll,” then copies Windows’ own schtasks.exe to disguise persistence setup.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malicious “NppExport.dll” is tracked as LUNCHPOKE, a tool that builds a hidden Libraries folder, extracts a password-protected “updater.rar” containing “RemoteLibUpdater.exe” and “InitTest.dll,” then copies Windows’ own schtasks.exe to disguise persistence setup.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
It registers a scheduled task under a randomized name to relaunch RemoteLibUpdater.exe every three minutes with the arguments 'setup nodisplay.'
У згаданому архіві міститься VBS-скрипт... у разі запуску скрипт забезпечить завантаження файлу-приманки...
Inside sits a double-extension VBS script disguised as a PDF, often padded with extra spaces before the real '.vbs' extension to trick careless readers.
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojanized Notepad++ plugin DLL used as the initial payload dropper. It creates a hidden folder, extracts follow-on components, and sets up disguised scheduled-task persistence.
A malicious DLL disguised as a Notepad++ plugin that establishes persistence by creating scheduled tasks and extracting additional payload components from an embedded archive.
DLL-based loader disguised as the Notepad++ plugin NppExport.dll. It extracts a password-protected archive, deploys RemoteLibUpdater.exe and InitTest.dll, copies schtasks.exe for persistence support, and creates a scheduled task to repeatedly launch the next-stage payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.