Suspicious Child Process Spawned by Notepad++ Updater GUP

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the Notepad++ updater GUP.exe spawning a command shell, curl or a secondary update.exe process. The Notepad++ supply chain attack abused GUP.exe to launch downstream execution chains and a Cobalt Strike loader as documented by Kaspersky. The trusted updater spawning these child processes indicates a compromised update and supply chain execution.

Related detections9 linkedT1059.003 — drag to rearrange
Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Suspicious Host Reconnaissance Command Chain via cmd
Suspicious Execution From Hidden fonts-unix Directory in tmp on Linux
Suspicious Malicious MCP Package devtools-assistant Execution (via process_creation)
Suspicious PIF AutoIt Interpreter Executing a3x Compiled Script
Malicious Netcat SSL Reverse Shell Execution via process_creation
Suspicious Executable Execution From Users Public Directory via Process Creation
Suspicious Bun Runtime Spawned by Node During npm Lifecycle
Malicious IIS w3wp Worker Spawning Command Interpreter via SharePoint Web Shell
Suspicious Child Process Spawned by Notepad++ Updater GUP
Pivot detection · T1059.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.