Malicious Notepad++ Google ads evade detection for months

A recent malvertising effort on Google Search uses sophisticated ways to avoid detection and analysis as it targets users who want to download the well-known Notepad++ word editor.

Malicious actors have been exploiting Google Ads more frequently to advertise phony software websites that propagate malware through malvertising campaigns.

The Notepad++ malvertising campaign has been active for a few months, but Malwarebytes, who first discovered it, claims that it has remained hidden for that entire period.

Although the exact payload that was sent to the victims is unknown, Malwarebytes believes it was most likely Cobalt Strike

