A watering hole attack compromised EmEditor's download page in late December 2025, distributing malware-laden installers to users. The malicious MSI file deployed multistage PowerShell payloads capable of credential theft, data exfiltration, disabling security telemetry, and establishing command-and-control communication.

6m read time From trendmicro.com
Post cover image

Sort: