This page was machine-translated and may differ from the original. View original
Notepad++ Supply Chain Attack: 3 Additional Undisclosed Infection Chains Confirmed
Attack infrastructure to be replaced multiple times between July and October 2025… Difficult to detect some attacks with existing intelligence
It has been suggested that the supply chain attack targeting Notepad++ update infrastructure was not a single incident, but a complex attack that unfolded in stages over several months.
According to analysis by security researchers, the impact appears not to have been limited, as attackers targeted multiple countries and organizations while changing their infrastructure and methods over time.
On February 9, 2026, Kaspersky announced, based on the findings of its Global Research and Analysis Team (GReAT), that the attackers behind the recent Notepad++ supply chain attacks targeted government agencies in the Philippines, financial institutions in El Salvador, IT service providers in Vietnam, and individual users across the three countries.
They explained that at least three different infection chains were used in this process, two of which had never been disclosed externally.
Analysis results showed that attackers have been completely changing their malware, command and control (C2) infrastructure, and delivery methods at intervals of about one month between July and October 2025.
The attack cases documented to date correspond to the final stage of the overall attack flow, and it has been determined that intrusions occurred in a completely different manner during the preceding stages.
The Notepad++ development team previously disclosed that the update infrastructure was compromised due to an incident involving a hosting provider on February 2, 2026.However, existing public reports focus on malware observed in October 2025, so it is possible that many organizations were unaware of the indicators of compromise used from July to September.
It was confirmed that each attack chain used different malicious IP addresses, domains, execution methods, and payloads. Accordingly, analysis suggests that if inspections were conducted based solely on the indicators of compromise released in October, traces of infection from previous stages cannot be ruled out.
Kaspersky GReAT researchers explained that based on the fact that attackers have frequently replaced their infrastructure and tools, there is a possibility that additional attack chains that have not yet been discovered exist.
This case demonstrates that supply chain attacks do not end in the short term but can continue covertly over a long period, highlighting the limitations of responses that rely on single-point indicators of compromise.
According to analysis by security researchers, the impact appears not to have been limited, as attackers targeted multiple countries and organizations while changing their infrastructure and methods over time.
On February 9, 2026, Kaspersky announced, based on the findings of its Global Research and Analysis Team (GReAT), that the attackers behind the recent Notepad++ supply chain attacks targeted government agencies in the Philippines, financial institutions in El Salvador, IT service providers in Vietnam, and individual users across the three countries.
They explained that at least three different infection chains were used in this process, two of which had never been disclosed externally.
Analysis results showed that attackers have been completely changing their malware, command and control (C2) infrastructure, and delivery methods at intervals of about one month between July and October 2025.
The attack cases documented to date correspond to the final stage of the overall attack flow, and it has been determined that intrusions occurred in a completely different manner during the preceding stages.
The Notepad++ development team previously disclosed that the update infrastructure was compromised due to an incident involving a hosting provider on February 2, 2026.However, existing public reports focus on malware observed in October 2025, so it is possible that many organizations were unaware of the indicators of compromise used from July to September.
It was confirmed that each attack chain used different malicious IP addresses, domains, execution methods, and payloads. Accordingly, analysis suggests that if inspections were conducted based solely on the indicators of compromise released in October, traces of infection from previous stages cannot be ruled out.
Kaspersky GReAT researchers explained that based on the fact that attackers have frequently replaced their infrastructure and tools, there is a possibility that additional attack chains that have not yet been discovered exist.
This case demonstrates that supply chain attacks do not end in the short term but can continue covertly over a long period, highlighting the limitations of responses that rely on single-point indicators of compromise.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)













