New Watering Hole Attacking EmEditor User with Stealer Malware
## Security Threat Targeting EmEditor Users
Security Threat Targeting EmEditor Users
A significant security threat has emerged affecting developers using EmEditor, a widely used text editor within Japanese programming communities.
In late December 2025, the official download page for EmEditor was compromised, enabling attackers to distribute malicious versions of the installer to unsuspecting users. This incident illustrates the potential risks associated with trusted software platforms being used as vectors for sophisticated malware.
The modified installer delivers a multistage malware payload focused on credential theft, data harvesting, and network infiltration. The compromised .MSI installer file executes scripts without triggering security alerts. Upon execution, a PowerShell command retrieves obfuscated code from domains mimicking authentic EmEditor infrastructure. The malware downloads additional payloads for establishing persistence and collecting system information.
A significant security threat has emerged affecting developers using EmEditor, a widely used text editor within Japanese programming communities.
The malware employs advanced string manipulation techniques to evade automated security analysis. The first payload retrieves main malware components responsible for credential harvesting, security software detection, and system fingerprinting. The second payload disables PowerShell Event Tracing for Windows to prevent security logging, while the third payload manages command-and-control communications, performing geofencing checks to exclude specific regions.
Trend Micro analysts identified this supply chain attack during threat intelligence operations, providing comprehensive technical analysis of the malware's construction and capabilities. The malware includes a campaign identifier to assist researchers in tracking affected systems and coordinating industry-wide response efforts.
Further technical analysis revealed that the compromised installer triggers a PowerShell command to retrieve the initial payload from a domain resembling legitimate infrastructure. Additional payloads establish persistence and initiate system information collection, employing sophisticated obfuscation techniques to avoid early detection systems.
Based on reporting by Cyber Security News.
