الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky uncovers hidden attack chains in Notepad++ supply chain compromise

Kaspersky Global Research and Analysis Team (GReAT) researchers have uncovered a Notepad++ supply-chain compromise that, while observed in organizations across Asia and Latin America, highlights a risk equally relevant to Middle East governments, financial institutions and service providers that rely on widely used software tools.
GReAT researchers discovered that attackers targeted a government organization in the Philippines, a financial institution in El Salvador, an IT service provider in Vietnam and individuals across three countries using at least three distinct infection chains — two of which remain unknown to the public.
The attackers completely overhauled their malware, command-and-control infrastructure and delivery methods roughly every month between July and October 2025. The single attack chain publicly documented to date represents only the final phase of a much longer and more sophisticated campaign.
The Notepad++ developers disclosed on February 2, 2026, that their update infrastructure had been compromised due to a hosting provider incident. Previous public reporting focused exclusively on malware observed in October 2025, leaving organizations unaware of the entirely different indicators of compromise used from July through September.

Each chain used different malicious IP addresses, domain names, execution methods and payloads. Organizations that scanned only for the October indicators may have missed earlier infections entirely. Kaspersky solutions blocked all identified attacks as they occurred.
“Defenders who checked their systems against the publicly known IoCs and found nothing should not assume they’re in the clear,” said Georgy Kucherin, senior security researcher at Kaspersky GReAT. “The July-September infrastructure was completely different — different IPs, different domains, different file hashes. And given how frequently these attackers rotated their tooling, we cannot rule out the existence of additional, as-yet-undiscovered chains.”
While the confirmed victims were located outside the Middle East, the campaign’s characteristics mirror the exact threat models facing Middle East governments, banks and critical service providers. The region’s heavy reliance on widely used developer and IT administration tools, combined with accelerated digital transformation initiatives, makes similar supply-chain attacks both plausible and difficult to detect.
For organizations in the Middle East, the campaign serves as a warning that geographically distant incidents can still expose blind spots in software trust, update verification and long-term threat hunting, Kaspersky experts observed.
Kaspersky GReAT has published the full list of indicators of compromise, including six malicious updater hashes, 14 C2 URLs and eight malicious file hashes not previously reported. The complete IoC list and technical analysis are available at Securelist.

Related Posts:

Kaspersky unveils how the worst cyber incidents hit SMBs over the past year

Turkish Airlines Named Liverpool FC Main Partner from 2027/28 Season

The Investor 2026 to Tackle Egypt’s Industry and Real Estate Challenges

Tanmeyah Receives Gold Client Protection Certification from MicroFinanza Rating

Bloom Holding Launches Alhambra, the Vibrant Heart and Final Release of Bloom Living

GovAcademy’s Executive Director joins the summit’s opening sessions as Abu Dhabi’s approach to skills intelligence takes centre stage

Zerosploit MEA and Comforte Announce Strategic Data Security Partnership

Al Seer Marine Capitalises on Strong Tanker Values with Profitable Sale of VLCC

آخر الأخبار
Kaspersky unveils how the worst cyber incidents hit SMBs over the past year وزير الشباب والرياضة يبحث مع «Blue Ribbon» تطوير إدارة وتشغيل الأندية الرياضية كاسبرسكي: 86% من الشركات الصغيرة والمتوسطة تعرضت لهجمات سيبرانية «عوده للتطوير» تطرح كمبوند «كناري» في الحي 25 بالعبور الجديدة على مساحة 15 فدانا Turkish Airlines Named Liverpool FC Main Partner from 2027/28 Season الذهب يعاود الصعود في مصر.. عيار 21 يسجل 6300 جنيه الخطوط الجوية التركية شريك رئيسي لنادي ليفربول من موسم 2027/2028 تيلدا تتيح إرسال واستقبال الأموال عبر إنستاباي بدعم موديوباي وزارة الصحة تنظم اليوم العلمي لمناقشة المجلة العلمية لمركز المعلومات الدوائية ديبال تتصدر سوق السيارات الكهربائية ممتدة المدى في مصر.. 1,135 سيارة منذ بداية العام جي بي أوتو تطلق هافال V7 في مصر.. تصميم صندوقي جريء وقدرات متقدمة على الطرق الوعرة وخياران من أنظمة ... البنك العربي يوقع اتفاقية تمويل مع شركة إيديتا للصناعات الغذائية بقيمة 600 مليون جنيه مصري رئيس الوزراء يهنيء مزارعي مصر بمناسبة الاحتفال بالعيد الـ ٧٤ للفلاح «CACC» وأكاديمية مصر للطيران للتدريب توقعان بروتوكول تعاون لتطوير الكوادر البشرية بقطاع الشحن الجوي 50 عدّاءً إماراتيًا يحملون رسالة العطاء إلى بكين ضمن سباق زايد الخيري وماراثون هوايرو سور الصين العظ... إبسون تفتتح مقرها الإقليمي للشرق الأوسط وشمال إفريقيا في المملكة العربية السعودية وزير التخطيط يبحث دعم رواد الأعمال المصريين في الإمارات مؤتمر Money2020 Middle East يستعرض في الرياض جدول أعمال نسخة 2026 مع مشاركة قادة التقنية المالية وال... وزيرة الأسرة: الميثاق يجسد رؤية الإمارات الاستباقية في تعزيز استقرار وتماسك الأسرة تيك توك يحذف 15.5 مليون فيديو مخالف.. العراق ومصر في الصدارة