logo

Black Cat Hacker Group Uses Fake Notepad++ Websites to Distribute Malware and Steal Data

ID: 6c925357-84c0-522c-b156-60ade3d553b7

STIX ID: report--6c925357-84c0-522c-b156-60ade3d553b7

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A Black Cat cybercriminal campaign used SEO-poisoned fake Notepad++ download sites and multi-stage redirects to deploy a custom data-stealing backdoor. The malware achieves persistence via registry startup entries and DLL side-loading, decrypts and reflectively loads payloads (e.g., M9OLUM4P.1CCE), and communicates with C2 at sbido.com; researchers reported ~277,800 compromised servers in China with daily botnet peaks over 62,000.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.