Beware of Malicious Notepad++ Websites that Attack Developers
released on 2024-03-28 @ 12:34:27 PM
A recent cybersecurity investigation uncovered threat actors actively targeting developers by distributing trojanized versions of the popular Notepad++ text editor through malicious websites. The malicious versions aim to infect victims with malware such as Cobalt Strike-like backdoors. The threat actors are leveraging online advertising and search engine optimization techniques to promote the malicious websites and lure victims. Technical analysis revealed inconsistencies in website URLs, titles, and content pointing to a network of interconnected threat actor-controlled domains used to distribute the malware.