Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)

Alerts when Notepad++ gup.exe spawns command/scripting or utility processes using suspicious tool keywords on Windows.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-02-03
Updated
2026-07-31
title: "Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)"
id: 1a4c3e70-1155-4cb6-ad94-baf554d10dcd
status: experimental
description: This rule flags Windows process creation events where the Notepad++ updater binary (gup.exe) spawns a suspicious child process. It focuses on child images commonly used for command execution and script handling (cmd.exe, powershell.exe/pwsh, cscript/wscript, mshta.exe) and CLI patterns associated with common download or execution tooling (bitsadmin, certutil, curl, wget, regsvr32, rundll32, forfiles, etc.). This matters because abused updaters can use spawned processes to execute or stage unwanted payloads; the detection relies on process creation telemetry including parent image, child image, and command line.
references:
  - https://notepad-plus-plus.org/news/v889-released/
  - https://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html
  - https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
  - https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/
  - https://securelist.com/notepad-supply-chain-attack/118708/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_gup_susp_child_process.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-02-03
tags:
  - attack.collection
  - attack.credential-access
  - attack.t1195.002
  - attack.initial-access
  - attack.t1557
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: \gup.exe
  selection_child_img:
    Image|endswith:
      - \cmd.exe
      - \powershell.exe
      - \pwsh.exe
      - \cscript.exe
      - \wscript.exe
      - \mshta.exe
  selection_child_cli:
    CommandLine|contains:
      - bitsadmin
      - certutil
      - curl
      - finger
      - forfiles
      - regsvr32
      - rundll32
      - wget
  condition: selection_parent and 1 of selection_child_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: bb0e87ce-c89f-4857-84fa-095e4483e9cb
    type: derived