logo

Trusted Tool, Hidden Threat: Official EmEditor Installer Hijacked to Push Malware

ID: eac3d437-e218-5baa-9cb8-a9f082954e5b

STIX ID: report--eac3d437-e218-5baa-9cb8-a9f082954e5b

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ddos

...
...

TrendAI Research discovered a supply-chain compromise of the EmEditor Windows installer in late December 2025: a trojanized MSI spawned a PowerShell first stage that fetched additional modules from deceptive regional domains, delivering multi-stage espionage malware that harvests credentials, disables PowerShell ETW for defense evasion, and prepares lateral movement; domain indicators and geofencing that excludes several CIS countries led analysts to assess a likely Russian/CIS-linked actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.