Malicious Ads Targeting Chinese Users with Fake Notepad++ and VNote Installers

Malicious advertisements and fake links are being directed towards Chinese people searching for genuine software on search engines like Baidu, such as Notepad++ and VNote. The purpose of these attempts is to spread trojanized versions of the software and eventually launch Geacon, which is a Golang-based variant of Cobalt Strike.

According to Kaspersky researcher Sergey Puzan, “the malicious site found in the notepad++ search is distributed through an advertisement block.”

Upon opening it, a perceptive viewer will quickly spot a humorous discrepancy: the graphic proudly displays Notepad++, while the website address has the line vnote. The title promotes a download of Notepad‐‐ (an analog of Notepad++, also released as open-source software). Notepad is really included with the packages that can be downloaded from this link read more Malicious Ads Targeting Chinese Users with Fake Notepad++ and VNote Installers.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *