216.73.216.6

Watering Hole Attack Targets EmEditor Users With Information-Stealing Malware

· Published 23/01/2026 11:47 · Modified 23/01/2026 23:17

Export JSON

Essential information

Published
23/01/2026 11:47
Modified
23/01/2026 23:17
Tags
2026-01-23 emeditor evelyn stealer geofencing information-stealing multistage malware powershell software supply chain watering hole
Related entities
3 observables, 8 techniques (mitre), 7 others

Description

A compromised installer was used in a attack to deliver . The attack, discovered in late December 2025, targeted users of this widely-used text editor. The malware performs credential theft, data exfiltration, and enables lateral movement. It uses obfuscated scripts and techniques, suggesting possible Russian origin. The malware disables security features, gathers system information, and exfiltrates data to a command-and-control server. This incident highlights the importance of validating installer integrity, monitoring usage, preserving endpoint telemetry, and enforcing least privilege principles. Software publishers are advised to secure download infrastructure and prepare incident response plans.

External references