logo

Malicious Ads Targeting Chinese Users with Fake Notepad++ and VNote Installers

ID: dcdd2fa2-8eaf-5c3b-b8fd-f5121c15e0cc

STIX ID: report--dcdd2fa2-8eaf-5c3b-b8fd-f5121c15e0cc

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-03-15

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Malvertising campaigns targeting Chinese users searching for Notepad++ and VNote are distributing trojanized installers that deploy a Golang-based Geacon-like backdoor; malicious packages are hosted on cloud storage domains and include modified Notepad-- installers that fetch the next-stage payload. The backdoor supports HTTPS C2 and a wide range of remote-control capabilities (SSH, file operations, process enumeration, clipboard access, execution, upload/download, screenshots), and the report also links this activity to other malvertising-distributed malware such as FakeBat/EugenLoader.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.