PULSE NAME
Investigation on the EmEditor Supply Chain attack
WHITE PetrP.73 2026-02-16 Modified: 2026-03-18
23
IOCs
MEDIUM VOLUME
The investigation into the EmEditor supply chain attack, highlighted in a report by Trend Micro, revolves around a rare type of cyber threat known as a watering hole attack, which specifically targets users of the EmEditor software. This tactic typically involves compromising websites frequented by the intended victims to serve malicious content or payloads. During the analysis phase, passive DNS resolution techniques were employed to trace additional IPs associated with the attack. The initial examination did not reveal any further URLs directly related to the command and control (C2) server identified by Trend Micro, which was http://cachingdrive.com, particularly the URL path "/gate/init". However, the investigation led to the discovery of a different domain with the path "/gate/start/", linked to a suspicious URL: hxxp://nc7d8p7u8j3n4hgm.com/gate/start/efeb550a. This suggests a potential expansion of the attack's infrastructure or alternative entry points.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (23)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2026-21858 2026-02-16
FileHash-MD5 7db4d84e579f0aad131bf32d55abf267 MD5 of ceb31976b8040cad5d5db3856466d198d3c0ea5bc904ae05c509b3b6de72e1c8 2026-02-16
FileHash-MD5 b97d5024adab17ceffe134f9ea877bf5 2026-02-16
FileHash-MD5 d3c0ea5bc904ae05c509b3b6de72e1c8 2026-02-16
FileHash-SHA1 4c873cb2b661b9356a32eae67a5bf76177be4b1c SHA1 of ceb31976b8040cad5d5db3856466d198d3c0ea5bc904ae05c509b3b6de72e1c8 2026-02-16
FileHash-SHA256 ceb31976b8040cad5d5db3856466d198d3c0ea5bc904ae05c509b3b6de72e1c8 2026-02-16
URL http://nc7d8p7u8j3n4hgm.com/gate/start/efeb550a. 2026-02-16
URL http://validin.com/ 2026-02-16
URL https://keyactivate.cc:443/gate/start/e805d522 2026-02-16
URL https://n8n.kraski-event.ru:443/gate/start/e805d522 2026-02-16
URL https://nc7d8p7u8j3n4hgm.com/gate/init/efeb550a/ 2026-02-16
domain cachingdrive.com 2026-02-16
domain emeditorde.com 2026-02-16
domain emeditorgb.com 2026-02-16
domain emeditorjapan.com 2026-02-16
domain emeditorjp.com 2026-02-16
domain emeditorltd.com 2026-02-16
domain emedjp.com 2026-02-16
domain emedorg.com 2026-02-16
domain keyactivate.cc 2026-02-16
domain nc7d8p7u8j3n4hgm.com 2026-02-16
domain validin.com 2026-02-16
hostname n8n.kraski-event.ru 2026-02-16