The app you trust is now the thing carrying the malware
If you or your team downloads software directly from the web, a signed, familiar application is no longer proof that what runs is safe. Two separate findings this week land on the same uncomfortable point: attackers have stopped needing a vulnerability in your software. They are using software you already trust as the delivery van.
A real copy of Notepad++, carrying a passenger
Ukraine's national response team, CERT-UA, has documented a campaign that ships a genuine, unmodified copy of Notepad++, the popular free text editor, alongside a malicious add-on. The editor itself is clean. The trick is the plugin sitting next to it.
The chain starts with a ZIP file containing a script dressed up to look like a PDF. Open it, and it quietly pulls down a second archive. Inside is a complete legitimate copy of Notepad++, plus a malicious plugin file, plus a password-protected archive and a real copy of the WinRAR compression tool. The script installs everything into a randomly named folder, launches Notepad++, and the editor loads the malicious plugin through its normal, designed-for-this plugin mechanism. From there a loader unpacks the next stage, sets up a scheduled task so it survives a reboot, and phones home for instructions.
No part of this exploited a hole in Notepad++. The editor did exactly what it is built to do: load a plugin placed beside it. That is the whole point. Antivirus and staff alike are looking for a bad program, and what arrived was a good one with bad company.
The campaign is attributed to a group linked to Sandworm, a Russian military intelligence operation, and its current targets are in Ukraine. Do not file this under "someone else's problem" for that reason. The technique is the story, and techniques travel. Bundling a clean, trusted application with a malicious sidecar is cheap, effective, and copied fast.
On a Mac, the swap can happen with no warning at all
A day earlier, researchers at Mysk disclosed a macOS weakness that reaches the same destination by a different road. Normally macOS guards installed apps closely: even a program running as an administrator cannot quietly rewrite the insides of another app, and any attempt throws up a warning. The researchers found a way around that. A malicious script running as the ordinary logged-in user, no password, no admin rights, can silently replace the main program file inside a trusted app you downloaded, then relaunch it with no security prompt.
The consequence is worse than a swapped program. Because the app keeps its real name and icon, the imposter can request access to your Keychain of saved passwords, and to protected folders like Desktop and Documents, and the system's permission prompt shows the trusted app's identity, not the attacker's. You approve, reasonably, because the box says an app you installed is asking. Apple reviewed the report and decided it does not warrant a fix.
Why this matters to a UK small business
The common thread is the bit that should worry you. "It is a program I recognise, and it is signed, so it is safe" was always a rough rule of thumb, and both findings quietly retire it.
Most offices run on trust in familiar software. Staff download a well-known free tool because it is well known. IT waves through an update because the app is one it has always used. Neither of those instincts is stupid, and neither is enough on its own any more. The malware is not pretending to be a bad program you would refuse. It is arriving inside, or wearing the face of, a good one you already welcomed.
The exposure is ordinary, not exotic. A member of staff grabbing a free utility from a search result. A developer or a curious colleague opening a "sample" someone sent them. A Mac user who ran one dodgy script months ago and has trusted every app on the machine ever since.
What to check
Control where software comes from. The cheapest defence is to shrink the number of people who install arbitrary software from the open web. On Windows, staff should not be local administrators on their day-to-day machines unless there is a real reason. On Macs, steer people to the App Store or your managed software list rather than downloading tools from search results. If you use an MSP, ask them: who can install software on our machines, and where are they allowed to get it from?
Get software from the source, not the search result. When a free tool like Notepad++ is genuinely needed, download it from the official website, never from a bundle someone sent or a link in an email. A legitimate installer never arrives as a ZIP full of extra pieces with a script dressed up as a document.
Keep the everyday tools patched. CERT-UA's advice for this campaign is plain: update Notepad++, WinRAR, and 7-Zip to current versions. The same goes for the browser and its extensions. Auto-update where you can, and put the handful that cannot auto-update on someone's monthly list.
Treat "I did not install anything" as unreliable. Both findings run without an obvious install step and without a warning. If a machine starts behaving oddly, a quiet swap or a sideloaded add-on is now a plausible cause, not a far-fetched one. On a Mac that has ever run an untrusted script, be sceptical of a permission prompt that seems to come from an app out of nowhere.
How Steelwise can help
Working out who can install what across your machines, and closing the easy routes in without turning your team into a helpdesk queue, is the kind of review we do. Get in touch.