LUNCHPOKE is a Windows dropper used by the Russia-aligned UAC-0099 threat cluster in campaigns targeting Ukrainian organizations. It is deployed as a malicious DLL masquerading as a Notepad++ plugin and is loaded through Notepad++’s normal plugin-loading mechanism after victims execute a phishing-delivered, trojanized application package. LUNCHPOKE creates a working directory, uses a bundled WinRAR utility to unpack a password-protected archive, and deploys the BURNYBEAR loader and the MATCHBOIL.V2 loader. It establishes persistence by creating a scheduled task that repeatedly launches BURNYBEAR, and copies and renames a legitimate Windows task-scheduling utility to help disguise that setup. The wider UAC-0099 infection chain uses a Visual Basic Script disguised as a PDF document, decoy documents, and ZIP archives to induce execution. LUNCHPOKE supports follow-on payload deployment rather than exploiting a vulnerability in Notepad++ itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malicious “NppExport.dll” is tracked as LUNCHPOKE, a tool that builds a hidden Libraries folder, extracts a password-protected “updater.rar” containing “RemoteLibUpdater.exe” and “InitTest.dll,” then copies Windows’ own schtasks.exe to disguise persistence setup.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign, observed since mid-summer 2026, employs the newly identified LUNCHPOKE and BURNYBEAR malware, along with an updated version of the MATCHBOIL.V2 loader... launching the legitimate text editor causes the attacker-controlled “NppExport.dll” file to be loaded automatically. The malicious DLL is classified as LUNCHPOKE.
The UAC-0099 campaign employs a novel approach by distributing a ZIP archive containing Notepad++ version 8.8.3 alongside a malicious plugin named LunchPoke (NppExport.dll). This plugin is loaded by Notepad++ through its standard mechanism, allowing the attackers to create scheduled tasks and deploy further malware.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
LUNCHPOKE, the DLL is designed to unpack the RAR archive... to a specific directory, set up persistence by means of a scheduled task to run "RemoteLibUpdater.exe" every three minutes.
LUNCHPOKE copies them to a specific directory and creates a scheduled task that runs RemoteLibUpdater.exe every three minutes.
The archive contains a Visual Basic Script (VBS) file...
The archive contains a Visual Basic Script (VBS) file... Once executed, the VBS script downloads a decoy PDF document... along with another archive named “Evernote.zip.”
The archive contains a Visual Basic Script (VBS) file that employs a double-extension technique. Although the file appears to the user as a PDF document named “Factory District.pdf,” a long sequence of spaces conceals its actual “.vbs” extension.
It then creates a copy of schtasks.exe, the legitimate Windows Task Scheduler utility and misleadingly renames it “Background.exe.”
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a component of the CERT-UA-documented infection chain; no capabilities are described in this content.
A malicious DLL disguised as a Notepad++ plugin (NppExport.dll) that is side-loaded by the legitimate Notepad++ application. It creates a working directory, extracts additional components from a password-protected archive, deploys RemoteLibUpdater.exe and InitTest.dll, copies schtasks.exe as Background.exe, and establishes persistence via a scheduled task.
A malicious DLL delivered as a fake Notepad++ plugin that extracts a protected archive, deploys additional components, and creates persistence via a scheduled task that repeatedly launches the next-stage loader.
A malicious Notepad++ plugin DLL masquerading as NppExport.dll that unpacks a password-protected archive, drops additional components, and establishes persistence via a scheduled task.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.