What’s in your notepad? Infected text editors target Chinese users
ID: 24c4af43-429e-55db-8d3e-f0e88e41b584
STIX ID: report--24c4af43-429e-55db-8d3e-f0e88e41b584
Feed Name: Securelist by Kaspersky
Researchers discovered a malvertising campaign on a major Chinese search engine distributing trojanized installers for Notepad-- and VNote that launch an updater which fetches a Geacon/CobaltStrike-like backdoor (DPysMac64) from update.transferusee.com. The backdoor (macOS/Linux variants) communicates with C2 at dns.transferusee.com over HTTPS and supports remote commands including file upload/download, screenshots, process control, persistence and SSH tunneling; the investigation links multiple fake sites and installers to the same infrastructure and provides file/URL indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
