PULSE NAME
Watering Hole Attack Targets EmEditor Users With Information-Stealing Malware
WHITE AlienVault 2026-01-23 Modified: 2026-01-23
17
IOCs
MEDIUM VOLUME
A compromised EmEditor installer was used in a software supply chain attack to deliver multistage malware. The attack, discovered in late December 2025, targeted users of this widely-used text editor. The malware performs credential theft, data exfiltration, and enables lateral movement. It uses obfuscated PowerShell scripts and geofencing techniques, suggesting possible Russian origin. The malware disables security features, gathers system information, and exfiltrates data to a command-and-control server. This incident highlights the importance of validating installer integrity, monitoring PowerShell usage, preserving endpoint telemetry, and enforcing least privilege principles. Software publishers are advised to secure download infrastructure and prepare incident response plans.
Indicators of Compromise (17)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 57bc24f923c92fc600c2ad47fe285074 2026-01-23
FileHash-MD5 6a4554509ce27efe5c6b8e58431f60d8 2026-01-23
FileHash-MD5 a27731876e769ff19e225700085967bf 2026-01-23
FileHash-SHA1 65b0853abb656c6cc342d87b872fbe21482e9bae 2026-01-23
FileHash-SHA1 81e1ccbd3b4ed5a7593cfba21315c65ad4635f73 2026-01-23
FileHash-SHA1 826af8619430e7363e9eb3b2395b36cf6365b7bd 2026-01-23
FileHash-SHA1 938325004e44ab1a65e948b4d07b05229309f630 2026-01-23
FileHash-SHA1 a3ab5e58a9330dd673dec17777e5110bf3c9eba3 2026-01-23
FileHash-SHA1 e5678fd66ac09205f55dc4fae9601185a76b2f50 2026-01-23
FileHash-SHA1 ff78a86746bdcc6ed1390ff291a6c599e96e8487 2026-01-23
FileHash-SHA256 3d1763b037e66bbde222125a21b23fc24abd76ebab40589748ac69e2f37c27fc 2026-01-23
FileHash-SHA256 4bea333d3d2f2a32018cd6afe742c3b25bfcc6bfe8963179dad3940305b13c98 2026-01-23
FileHash-SHA256 da59acc764bbd6b576bef6b1b9038f592ad4df0eed894b0fbd3931f733622a1a 2026-01-23
domain cachingdrive.com 2026-01-23
domain emeditorde.com 2026-01-23
domain emeditorgb.com 2026-01-23
domain emeditorjp.com 2026-01-23