module
Notepad++ Plugin Persistence
| Disclosed | Created |
|---|---|
| Dec 11, 2005 | Jan 15, 2026 |
Disclosed
Dec 11, 2005
Created
Jan 15, 2026
Description
This module create persistence by adding a malicious plugin to Notepad++, as it blindly loads and executes DLL from its plugin directory on startup, meaning that the payload will be executed every time Notepad++ is launched.
Author
msutovsky-r7
Platform
Windows
Architectures
x64, x86, aarch64
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.