الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky uncovers hidden attack chains in Notepad++ supply chain compromise

Kaspersky Global Research and Analysis Team (GReAT) researchers have uncovered a Notepad++ supply-chain compromise that, while observed in organizations across Asia and Latin America, highlights a risk equally relevant to Middle East governments, financial institutions and service providers that rely on widely used software tools.
GReAT researchers discovered that attackers targeted a government organization in the Philippines, a financial institution in El Salvador, an IT service provider in Vietnam and individuals across three countries using at least three distinct infection chains — two of which remain unknown to the public.
The attackers completely overhauled their malware, command-and-control infrastructure and delivery methods roughly every month between July and October 2025. The single attack chain publicly documented to date represents only the final phase of a much longer and more sophisticated campaign.
The Notepad++ developers disclosed on February 2, 2026, that their update infrastructure had been compromised due to a hosting provider incident. Previous public reporting focused exclusively on malware observed in October 2025, leaving organizations unaware of the entirely different indicators of compromise used from July through September.

Each chain used different malicious IP addresses, domain names, execution methods and payloads. Organizations that scanned only for the October indicators may have missed earlier infections entirely. Kaspersky solutions blocked all identified attacks as they occurred.
“Defenders who checked their systems against the publicly known IoCs and found nothing should not assume they’re in the clear,” said Georgy Kucherin, senior security researcher at Kaspersky GReAT. “The July-September infrastructure was completely different — different IPs, different domains, different file hashes. And given how frequently these attackers rotated their tooling, we cannot rule out the existence of additional, as-yet-undiscovered chains.”
While the confirmed victims were located outside the Middle East, the campaign’s characteristics mirror the exact threat models facing Middle East governments, banks and critical service providers. The region’s heavy reliance on widely used developer and IT administration tools, combined with accelerated digital transformation initiatives, makes similar supply-chain attacks both plausible and difficult to detect.
For organizations in the Middle East, the campaign serves as a warning that geographically distant incidents can still expose blind spots in software trust, update verification and long-term threat hunting, Kaspersky experts observed.
Kaspersky GReAT has published the full list of indicators of compromise, including six malicious updater hashes, 14 C2 URLs and eight malicious file hashes not previously reported. The complete IoC list and technical analysis are available at Securelist.

Related Posts:

Madinet Masr Awards EGP 1.38 Billion for Origami at Taj City

إدراج 47 جامعة مصرية في تصنيف UI GreenMetric للاستدامة لعام 2026

حجر أساس لمشروع أعلاف باستثمارات صينية.. والزراعة تؤكد دعم الشراكة مع القطاع الخاص

Zoho Launches Agent-Ready Catalyst Platform for AI App Development

Turkish Airlines Named Europe’s Best Airline for the 11th Time

NILEWOOD Expands in Saudi Arabia at Saudi Wood Show 2026

Turkish Airlines and Air China Expand Codeshare Agreement

PATRIZIA appoints Hassan Awada as Senior Executive Officer to lead and accelerate Middle East expansion

آخر الأخبار
اورنچ مصر ووادي دجلة تطلقان منظومة حلول ذكية بــ«نيو» في مستقبل سيتي أورنچ مصر وهواوي تطلقان أول تجربة عالمية لتقنية CCIC على شبكات الميكروويف بنك saib يرفع العائد على شهادة Excellence الثلاثية إلى 18.25% كوربوريت ستاك تنفذ مشروعًا لرقمنة 1000 مصنع بالتعاون مع مركز تحديث الصناعة الذكاء الاصطناعي في الفصول الدراسية.. كيف يتخيل الجيل Z مستقبل التعليم؟ ڤاليو تنجح في إتمام إصدار سندات توريق بقيمة 945.8 مليون جنيه إم إن تي-حالاࣧ تنجح فى إتمام مجموعة من إصدارات سندات التوريق بقيمة تتجاوز 4 مليار جنيه بنهاية الربع ... تنميه تتعاون مع«ايسكور»و«سينابس أناليتكس»لتطوير قرارات الائتمان بالذكاء الرقمي مع هيونداي توسان.. راحة بالك تمتد لـ3 سنوات أو 60 ألف كيلومتر مع باقة الصيانة الخاصة من جي بي أوتو قمة الابتكار الجامعي 2026 تعلن الفرق الفائزة بمشاركة 100 مشروع من 30 جامعة سالي سلامة أمام الاختبار الأصعب في نيسان مصر.. هل تعود الثقة من بوابة العميل والأمان؟ محافظ البنك المركزي يبحث مع مسؤول «التمويل الدولية» تعزيز التعاون المشترك وزير الأوقاف يلتقي المشرفات من الواعظات عبر تقنية الاتصال المرئي لمتابعة العمل الدعوي مصر تدين اقتحام المستوطنين الإسرائيليين للمسجد الأقصى المبارك بنك القاهرة وشركة فيزا يوقعان اتفاقية تعاون لدعم تطوير حلول ومنتجات دفع جديدة محافظ البنك المركزي ووزير الصناعة يطلقان صندوق إعادة هيكلة المصانع المتعثرة برأسمال مليار جنيه إف سي بايرن ميونخ يؤسس أكاديمية تعمل على مدار العام في الشرق الأوسط، ويقدّم نموذجه المتميز لتطوير ال... دولة الإمارات تجدد التزامها بالتنمية المستدامة خلال الاجتماع السنوي لمجلس محافظي البنك الآسيوي للاس... المكتب الطبي يعلن حصول «مستشفيات الشيخ خليفة» على اعتماد «مسار التميّز بامتياز» من «المركز الأمريكي ... مجموعة دلسكو تطلق برنامج «خطوة» للمواهب الوطنية لتطوير وتمكين الكفاءات الإماراتية