8 ms·
> Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests. I'd be curious to know if there was
by tragiclos 8mo ago
> Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.
I'd be curious to know if there was any pattern as to which users were targeted, but the post doesn't go into any further detail except to say it was likely a Chinese state-sponsored group.
- x_may 8mo agoIt might have been explicitly targeted, but they did say that there were older versions of Notepad ++ with ""insufficient update verification controls" so it might have just been there was only one subset of users actually susceptible to this.
- pavon 8mo agoNo, the additional update verification was added after this attack was discovered. All Notepad++ installations were vulnerable during the time of the hijacking campaign.
- buggymaaan 8mo agoI dont know who hacked the servers nor I do know how to find out. Let's blame state actors, who's going to come verify these claims.
- NedF 8mo ago[dead]
- IhateAI 8mo agoMy guess would be certain IPs associated with universities, corporations and government institutions.
- tragiclos 8mo agoThis article going into more detail on those targeted was posted later: https://securelist.com/notepad-supply-chain-attack/118708/ https://securelist.com/notepad-supply-chain-attack/118708/