Kaspersky Researchers Expose Evolving Malware Infrastructure in Notepad++ Breach

Kaspersky Global Research and Analysis Team (GReAT) researchers have discovered that attackers behind the Notepad++ supply chain compromise
Kaspersky Researchers Expose Evolving Malware Infrastructure in Notepad++ Breach
Published on
2 min read

Kaspersky Global Research and Analysis Team (GReAT) researchers have discovered that attackers behind the Notepad++ supply chain compromise targeted a government organization in the Philippines, a financial institution in El Salvador, an IT service provider in Vietnam and individuals across three countries using at least three distinct infection chains — two of which remain unknown to the public.

The attackers completely overhauled their malware, command-and-control infrastructure and delivery methods roughly every month between July and October 2025. The single attack chain publicly documented to date represents only the final phase of a much longer and more sophisticated campaign.

The Notepad++ developers disclosed on Feb. 2, 2026, that their update infrastructure had been compromised due to a hosting provider incident. Previous public reporting focused exclusively on malware observed in October 2025, leaving organizations unaware of the entirely different indicators of compromise used from July through September.

Each chain used different malicious IP addresses, domain names, execution methods and payloads. Organizations that scanned only for the October indicators may have missed earlier infections entirely. Kaspersky solutions blocked all identified attacks as they occurred.

"Defenders who checked their systems against the publicly known IoCs and found nothing should not assume they're in the clear," said Georgy Kucherin, senior security researcher at Kaspersky GReAT. "The July-September infrastructure was completely different — different IPs, different domains, different file hashes. And given how frequently these attackers rotated their tooling, we cannot rule out the existence of additional, as-yet-undiscovered chains."

Kaspersky GReAT has published the full list of indicators of compromise, including six malicious updater hashes, 14 C2 URLs and eight malicious file hashes not previously reported. The complete IoC list and technical analysis are available at Securelist.

𝐒𝐭𝐚𝐲 𝐢𝐧𝐟𝐨𝐫𝐦𝐞𝐝 𝐰𝐢𝐭𝐡 𝐨𝐮𝐫 𝐥𝐚𝐭𝐞𝐬𝐭 𝐮𝐩𝐝𝐚𝐭𝐞𝐬 𝐛𝐲 𝐣𝐨𝐢𝐧𝐢𝐧𝐠 𝐭𝐡𝐞 WhatsApp Channel now! 👈📲

𝑭𝒐𝒍𝒍𝒐𝒘 𝑶𝒖𝒓 𝑺𝒐𝒄𝒊𝒂𝒍 𝑴𝒆𝒅𝒊𝒂 𝑷𝒂𝒈𝒆𝐬 👉 FacebookLinkedInTwitterInstagram

Related Stories

No stories found.
logo
DIGITAL TERMINAL
digitalterminal.in