PULSE NAME
Watering Hole Attack Targets EmEditor Users With Information-Stealing Malware
WHITE AlienVault 2026-01-23 Modified: 2026-01-23
17
IOCs
MEDIUM VOLUME
A compromised EmEditor installer was used in a software supply chain attack to deliver multistage malware. The attack, discovered in late December 2025, targeted users of this widely-used text editor. The malware performs credential theft, data exfiltration, and enables lateral movement. It uses obfuscated PowerShell scripts and geofencing techniques, suggesting possible Russian origin. The malware disables security features, gathers system information, and exfiltrates data to a command-and-control server. This incident highlights the importance of validating installer integrity, monitoring PowerShell usage, preserving endpoint telemetry, and enforcing least privilege principles. Software publishers are advised to secure download infrastructure and prepare incident response plans.
Indicators of Compromise (3 / 17 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 57bc24f923c92fc600c2ad47fe285074 2026-01-23
FileHash-MD5 6a4554509ce27efe5c6b8e58431f60d8 2026-01-23
FileHash-MD5 a27731876e769ff19e225700085967bf 2026-01-23