logo

What’s in your notepad? Infected text editors target Chinese users

ID: 24c4af43-429e-55db-8d3e-f0e88e41b584

STIX ID: report--24c4af43-429e-55db-8d3e-f0e88e41b584

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-03-13

Date Updated: 2026-04-29

Author: Sergey Puzan

...
...

Researchers discovered a malvertising campaign on a major Chinese search engine distributing trojanized installers for Notepad-- and VNote that launch an updater which fetches a Geacon/CobaltStrike-like backdoor (DPysMac64) from update.transferusee.com. The backdoor (macOS/Linux variants) communicates with C2 at dns.transferusee.com over HTTPS and supports remote commands including file upload/download, screenshots, process control, persistence and SSH tunneling; the investigation links multiple fake sites and installers to the same infrastructure and provides file/URL indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.