

Inactive· since Feb 13, 2026
- 12
- days it ran
- 0
- relaunches
- 24,636
- EU reach
Ad copy
Kaspersky GReAT experts analyzed the supply chain attack involving trojanized updates of the popular Notepad++ editor, favored by many software developers. The attack lasted until December 2025. The attackers had ample resources to frequently change C2 addresses, significantly modify infection chains, and swap final malware payloads. According to our telemetry, from July to October 2025, at least three distinct infection chains were used. Known victims span Australia, Latin America, and Southeast Asia, including IT service providers, individuals, government entities, and financial organizations. One infection chain exploited a very old vulnerability in legitimate ProShow software to launch Metasploit payloads and Cobalt Strike beacons; another used Metasploit launched via Lua scripts; a third employed DLL sideloading to load malicious code within the BluetoothService context and deploy the Chrysalis backdoor. Kaspersky’s security solutions, such as Kaspersky Next, successfully detect all malware used by attackers. Notable clues to simplify threat hunting include the use of NSIS installers in the initial stage and connections to the unusual domain temp[.]sh across multiple infection chains. A comprehensive IOC list and additional detection recommendations are detailed here.
New IOCs in Notepad++ supply chain attack
Kaspersky GReAT experts discovered previously undocumented infection chains used in the Notepad++ supply chain attacks. The article provides new IoCs related to those incidents which employ DLL sideloading and Cobalt Strike Beacon delivery.
LEARN MORELike this ad? Make it yours.
Crush rebuilds this exact creative around your product — your brand, your colors, your offer — in about a minute.







