Between June and December 2025, nation-state actors compromised Notepad++'s hosting infrastructure to selectively deliver malware to government, telecom, and critical infrastructure targets across Southeast Asia, South America, the U.S., and Europe. The attackers exploited insufficient verification in the WinGUp updater to
•9m read time• From unit42.paloaltonetworks.com
Table of contents
Executive SummaryDetails of the Attack on Notepad++Interim GuidanceUnit 42 Managed Threat Hunting QueriesConclusionPalo Alto Networks Product ProtectionsIndicators of CompromiseSort: