216.73.216.6

Investigation on the EmEditor Supply Chain Cyberattack

· Published 09/02/2026 14:52 · Modified 09/02/2026 20:42

Export JSON

Essential information

Published
09/02/2026 14:52
Modified
09/02/2026 20:42
Tags
2026-02-09 command and control domain masquerading emeditor powershell supply chain attack watering hole
Related entities
4 observables, 3 techniques (mitre), 10 others

Description

A recent targeting users has been uncovered, involving tactics. The investigation reveals multiple domains masquerading as -related sites, all registered through NameSilo LLC in December 2025. The domains resolve to various IP addresses, with some changes observed in February 2026. Additional domains with similar patterns were discovered, along with peculiar HTTP header behavior. A potential early stage of the campaign was identified, sharing similar characteristics with the initial report. The attackers continued their activities even after exposure, utilizing scripts and various domains for purposes. The analysis provides a comprehensive list of indicators, including domain names, IP addresses, and file hashes associated with the attack.

External references