Related Threat Clusters
-
Nearly 300 Fake GitHub Repositories Distributing BoryptGrab Malware
Since late June 2026, nearly 300 fake GitHub repositories have been created, impersonating well-known software brands to distribute malware. The malware, a variant of BoryptGrab, targets Windows systems and is designed…
2 articles · Updated July 16, 2026 -
Artlist Subdomain Compromised in ClickFix Campaign Using EtherHiding Technique
In July 2026, a ClickFix campaign was discovered on the Artlist subdomain new-blog.artlist[.]io, where attackers injected malicious code that masqueraded as a CAPTCHA to install a Remote Access Trojan (RAT). The attack…
33 articles · Updated July 14, 2026 -
State-Sponsored Hackers Compromise Notepad++ Update Mechanism
Notepad++ has been hijacked by state-sponsored hackers, specifically a likely Chinese threat actor. The attackers compromised the software's update mechanism between June and December 2025, allowing them to redirect…
100 articles · Updated February 2, 2026 -
Notepad++ Update Mechanism Vulnerability Allows Malware Deployment
A critical vulnerability in Notepad++'s update mechanism, WinGUp, has been identified, allowing attackers to hijack network traffic and install malware disguised as legitimate updates. The development team has released…
3 articles · Updated December 12, 2025
Recent Intelligence Reports
- Nearly 300 New Fake GitHub Repositories Spread Malware — www.clubic.com · July 17, 2026
- Notepad++ Update Hijacking Linked to Hosting Provider Compromise — Infosecurity-Magazine · February 2, 2026
- Notepad++ reveals its updater was hijacked by state-sponsored hackers — Betanews · February 2, 2026
- Notepad++ releases emergency patch as hackers exploit updater to deploy malware — Cybernews · December 10, 2025