LUNCHPOKE is a Windows malware dropper implemented as a .NET DLL masquerading as a Notepad++ plugin. It is associated with UAC-0099, also tracked as Earth Sirrush, a Russia-aligned threat group targeting Ukrainian organizations. Documented in July 2026, LUNCHPOKE forms the opening malware stage of a chain deploying the BURNYBEAR loader and the updated MATCHBOIL.V2 loader.
The infection chain begins with phishing emails containing linked images that direct recipients through shortened links to file-sharing services. Downloaded ZIP archives contain a VBScript disguised as a PDF through a double extension and intervening spaces. Executing the script displays a decoy document, downloads a package containing legitimate Notepad++ components and a malicious plugin, extracts the package, and launches the editor. Notepad++ then loads LUNCHPOKE through its normal plugin mechanism. This execution method abuses legitimate application functionality rather than requiring a Notepad++ vulnerability or a compromise of its software distribution infrastructure.
LUNCHPOKE uses bundled WinRAR to extract BURNYBEAR and MATCHBOIL.V2 from a password-protected archive into a writable staging directory. It copies and renames the legitimate Windows task-scheduling utility and creates a scheduled task that executes BURNYBEAR every three minutes, establishing persistence for the subsequent stages. BURNYBEAR loads MATCHBOIL.V2, which can retrieve additional payloads. LUNCHPOKE's established role is payload deployment and persistence setup, rather than direct information theft or remote control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malicious “NppExport.dll” is tracked as LUNCHPOKE, a tool that builds a hidden Libraries folder, extracts a password-protected “updater.rar” containing “RemoteLibUpdater.exe” and “InitTest.dll,” then copies Windows’ own schtasks.exe to disguise persistence setup.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAC-0099 : nouveaux outils LUNCHPOKE, BURNYBEAR et MATCHBOIL.V2 via DLL hijacking Notepad++
In July 2026, CERT-UA documented another chain beginning with LUNCHPOKE, a malicious Notepad++ plugin.
The UAC-0099 campaign employs a novel approach by distributing a ZIP archive containing Notepad++ version 8.8.3 alongside a malicious plugin named LunchPoke (NppExport.dll). This plugin is loaded by Notepad++ through its standard mechanism, allowing the attackers to create scheduled tasks and deploy further malware.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
LUNCHPOKE, the DLL is designed to unpack the RAR archive... to a specific directory, set up persistence by means of a scheduled task to run "RemoteLibUpdater.exe" every three minutes.
LUNCHPOKE copies them to a specific directory and creates a scheduled task that runs RemoteLibUpdater.exe every three minutes.
The archive contains a Visual Basic Script (VBS) file...
The archive contains a Visual Basic Script (VBS) file... Once executed, the VBS script downloads a decoy PDF document... along with another archive named “Evernote.zip.”
The archive contains a Visual Basic Script (VBS) file that employs a double-extension technique. Although the file appears to the user as a PDF document named “Factory District.pdf,” a long sequence of spaces conceals its actual “.vbs” extension.
It then creates a copy of schtasks.exe, the legitimate Windows Task Scheduler utility and misleadingly renames it “Background.exe.”
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious .NET DLL masquerading as a Notepad++ plugin, listed among UAC-0099's tools used during April–July 2026. Its specific payload functionality is not described.
Uses DLL proxying to execute attacker code when Notepad++ starts. Deploys BURNYBEAR and MATCHBOIL.V2 as part of an espionage infection chain.
Malicious Notepad++ plugin that uses DLL proxying to execute attacker code when the editor starts. It deploys BURNYBEAR and MATCHBOIL.V2 as part of an espionage infection chain.
Named malware mentioned in the discussion of UAC-0099's infection chain, which involves malicious VBS files and legitimate Notepad++ components. Its specific capabilities are not described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.