Inside the EmEditor supply chain compromise
ID: f1e92311-879f-5d63-b156-e30d84c3d5e9
STIX ID: report--f1e92311-879f-5d63-b156-e30d84c3d5e9
Feed Name: ReversingLabs Blog
This technical investigation analyzes the December 2025 EmEditor software supply-chain compromise, detailing how adversaries modified MSI installers (overwriting installer actions and embedding VBScript/PowerShell stagers), exposed deterministic forensic artifacts in MSI SummaryInformation, and operated reusable C2 infrastructure; the report provides hashes, domains, IPs, URLs, timeline analysis, and mitigation recommendations for early domain monitoring and build/package integrity controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
