Trusted Tool, Hidden Threat: Official EmEditor Installer Hijacked to Push Malware
ID: eac3d437-e218-5baa-9cb8-a9f082954e5b
STIX ID: report--eac3d437-e218-5baa-9cb8-a9f082954e5b
Feed Name: securityonline.info
TrendAI Research discovered a supply-chain compromise of the EmEditor Windows installer in late December 2025: a trojanized MSI spawned a PowerShell first stage that fetched additional modules from deceptive regional domains, delivering multi-stage espionage malware that harvests credentials, disables PowerShell ETW for defense evasion, and prepares lateral movement; domain indicators and geofencing that excludes several CIS countries led analysts to assess a likely Russian/CIS-linked actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
