PULSE NAME
Investigation on the EmEditor Supply Chain Cyberattack
WHITE AlienVault 2026-02-09 Modified: 2026-03-11
13
IOCs
MEDIUM VOLUME
A recent supply chain attack targeting EmEditor users has been uncovered, involving watering hole tactics. The investigation reveals multiple domains masquerading as EmEditor-related sites, all registered through NameSilo LLC in December 2025. The domains resolve to various IP addresses, with some changes observed in February 2026. Additional domains with similar patterns were discovered, along with peculiar HTTP header behavior. A potential early stage of the campaign was identified, sharing similar characteristics with the initial report. The attackers continued their activities even after exposure, utilizing PowerShell scripts and various domains for command and control purposes. The analysis provides a comprehensive list of indicators, including domain names, IP addresses, and file hashes associated with the attack.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (13)
All FileHash-MD5 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 b97d5024adab17ceffe134f9ea877bf5 2026-02-09
FileHash-MD5 d3c0ea5bc904ae05c509b3b6de72e1c8 2026-02-09
FileHash-SHA256 ceb31976b8040cad5d5db3856466d198d3c0ea5bc904ae05c509b3b6de72e1c8 2026-02-09
domain cachingdrive.com 2026-02-09
domain emeditorde.com 2026-02-09
domain emeditorgb.com 2026-02-09
domain emeditorjapan.com 2026-02-09
domain emeditorjp.com 2026-02-09
domain emeditorltd.com 2026-02-09
domain emedjp.com 2026-02-09
domain emedorg.com 2026-02-09
domain keyactivate.cc 2026-02-09
domain nc7d8p7u8j3n4hgm.com 2026-02-09