Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security NachrichtenNew infosec products of the week: October 2, 2026(02.10.2026 um 06:00 Uhr)
•
IT Security NachrichtenERP-Migration: Kostenfalle Schnittstellen(02.10.2026 um 05:34 Uhr)
•
Android Tipps & SecurityAmazon reduziert eure Prime-Gebühr jetzt auf den alten Preis(02.10.2026 um 06:00 Uhr)
•••
Sicherheitslücken (CVE)CVE-2026-21140 | Samsung Devices access control (EUVD-2026-91157)(02.10.2026 um 05:08 Uhr)
••••
Sichere ProgrammierungWhat Can NSL Actually Do? — A Look at Nova Signal Language(02.10.2026 um 05:14 Uhr)
•
IT Security NachrichtenNew infosec products of the week: October 2, 2026(02.10.2026 um 06:00 Uhr)
•
IT Security NachrichtenERP-Migration: Kostenfalle Schnittstellen(02.10.2026 um 05:34 Uhr)
•
Android Tipps & SecurityAmazon reduziert eure Prime-Gebühr jetzt auf den alten Preis(02.10.2026 um 06:00 Uhr)
•••
Sicherheitslücken (CVE)CVE-2026-21140 | Samsung Devices access control (EUVD-2026-91157)(02.10.2026 um 05:08 Uhr)
••••
Sichere ProgrammierungWhat Can NSL Actually Do? — A Look at Nova Signal Language(02.10.2026 um 05:14 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

State-Sponsored Attack Hijacks Notepad++ Update Infrastructure to Deliver Malware

State-Sponsored Attack Hijacks Notepad++ Update Infrastructure to Deliver Malware Post Views: 1 Join our Patreon Channel and Gain access to 70+ Exclusive…

Beitrag
0
Seite
0
↗ Quelle (blackhatethicalhacking.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

























State-Sponsored Attack Hijacks Notepad++ Update Infrastructure to Deliver Malware



















































Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos.







Patreon

















Reading Time: 3 Minutes


















State-Sponsored Attack Hijacked Notepad++ Update Infrastructure


The maintainer of Notepad++ has confirmed that state-sponsored threat actors compromised the application’s update delivery mechanism, redirecting update traffic to malicious servers through an infrastructure-level breach.


According to Notepad++ developer Don Ho, the attackers did not exploit a vulnerability in the Notepad++ codebase itself. Instead, they compromised the hosting provider’s infrastructure, allowing them to intercept and manipulate update traffic intended for notepad-plus-plus.org.



“The attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,” Ho said.



The precise technical method used to redirect the traffic remains under investigation.


Targeted Update Redirection Campaign


The disclosure follows the release of Notepad++ version 8.8.9, which addressed an issue where WinGUp (the built-in updater) was intermittently redirected to malicious domains. Due to insufficient verification of the authenticity and integrity of downloaded update binaries, attackers capable of intercepting network traffic were able to substitute legitimate updates with trojanized executables.


Evidence suggests the campaign was highly targeted. Only select users had their update traffic redirected to rogue servers, where poisoned binaries were served. The attack is believed to have begun as early as June 2025, remaining undetected for over six months.







See Also: So, you want to be a hacker?

Offensive Security, Bug Bounty Courses

























Attribution and Infrastructure Compromise


Security researcher Kevin Beaumont linked the exploitation activity to threat actors operating from China, noting that the campaign was used to compromise systems and facilitate further network intrusions.


Further investigation revealed that the original hosting provider’s shared infrastructure was compromised until September 2, 2025. Even after the attackers lost direct server access, they retained credentials to internal services until December 2, 2025, enabling continued redirection of update traffic.









































Mitigation Measures


In response to the incident, the Notepad++ project has migrated its website and update infrastructure to a new hosting provider. The maintainer has emphasized that the breach was external to Notepad++ itself and stemmed from third-party infrastructure compromise.


Users are strongly advised to update to the latest Notepad++ version and verify the integrity of any downloaded binaries, especially if updates were installed during the affected timeframe.





























Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? If you want to express your idea in an article contact us here for a quote: [email protected]







Sources: thehackernews.com, notepad++ blog


Source Link







Merch




















Offensive Security & Ethical Hacking Course


Begin the learning curve of hacking now!





Information Security Solutions


Find out how Pentesting Services can help you.




Join our Community






The post State-Sponsored Attack Hijacks Notepad++ Update Infrastructure to Deliver Malware first appeared on Black Hat Ethical Hacking.
🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

Bedrohungsgraph · ATT&CK-Mapping · Exploit-Belege
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
9 Knoten · 8 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
14 Taktiken
1 belegte Technik
T1190TA0001 · Initial Access
Exploit Public-Facing Application
Mitigation: M1042 Network Segmentation & WAF Rule Enforcement
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten State-Sponsored Attack Hijacks Notepad++ Update Infrastructure to Deliver Malware

Thematisch verwandte Begriffe: StateSponsored, Attack, Hijacks, Notepad · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag