Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)
Alerts when Notepad++ gup.exe spawns command/scripting or utility processes using suspicious tool keywords on Windows.
- Product
- windows
- Category
- process_creation
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2026-02-03
- Updated
- 2026-07-31
ATT&CK techniques
Initial Access → CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events where the Notepad++ updater binary (gup.exe) spawns a suspicious child process. It focuses on child images commonly used for command execution and script handling (cmd.exe, powershell.exe/pwsh, cscript/wscript, mshta.exe) and CLI patterns associated with common download or execution tooling (bitsadmin, certutil, curl, wget, regsvr32, rundll32, forfiles, etc.). This matters because abused updaters can use spawned processes to execute or stage unwanted payloads; the detection relies on process creation telemetry including parent image, child image, and command line.
Reporting behind it
- notepad-plus-plus.orghttps://notepad-plus-plus.org/news/v889-released/
- heise.dehttps://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html
- rapid7.comhttps://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
- validin.comhttps://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/
- securelist.comhttps://securelist.com/notepad-supply-chain-attack/118708/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_gup_susp_child_process.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)"
id: 1a4c3e70-1155-4cb6-ad94-baf554d10dcd
status: experimental
description: This rule flags Windows process creation events where the Notepad++ updater binary (gup.exe) spawns a suspicious child process. It focuses on child images commonly used for command execution and script handling (cmd.exe, powershell.exe/pwsh, cscript/wscript, mshta.exe) and CLI patterns associated with common download or execution tooling (bitsadmin, certutil, curl, wget, regsvr32, rundll32, forfiles, etc.). This matters because abused updaters can use spawned processes to execute or stage unwanted payloads; the detection relies on process creation telemetry including parent image, child image, and command line.
references:
- https://notepad-plus-plus.org/news/v889-released/
- https://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html
- https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
- https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/
- https://securelist.com/notepad-supply-chain-attack/118708/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_gup_susp_child_process.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-02-03
tags:
- attack.collection
- attack.credential-access
- attack.t1195.002
- attack.initial-access
- attack.t1557
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: \gup.exe
selection_child_img:
Image|endswith:
- \cmd.exe
- \powershell.exe
- \pwsh.exe
- \cscript.exe
- \wscript.exe
- \mshta.exe
selection_child_cli:
CommandLine|contains:
- bitsadmin
- certutil
- curl
- finger
- forfiles
- regsvr32
- rundll32
- wget
condition: selection_parent and 1 of selection_child_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: bb0e87ce-c89f-4857-84fa-095e4483e9cb
type: derived