Malicious Ads Targeting Chinese Users with Fake Notepad++ and VNote Installers
ID: dcdd2fa2-8eaf-5c3b-b8fd-f5121c15e0cc
STIX ID: report--dcdd2fa2-8eaf-5c3b-b8fd-f5121c15e0cc
Feed Name: The Hacker News
Malvertising campaigns targeting Chinese users searching for Notepad++ and VNote are distributing trojanized installers that deploy a Golang-based Geacon-like backdoor; malicious packages are hosted on cloud storage domains and include modified Notepad-- installers that fetch the next-stage payload. The backdoor supports HTTPS C2 and a wide range of remote-control capabilities (SSH, file operations, process enumeration, clipboard access, execution, upload/download, screenshots), and the report also links this activity to other malvertising-distributed malware such as FakeBat/EugenLoader.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
