- 0 Posts
- 5 Comments
pez@piefed.blahaj.zoneto
Technology@lemmy.world•Notepad++ Hijacked by State-Sponsored HackersEnglish
1·4 months agoI mean IOCs that you can scan for in an environment to see if a machine has been compromised using this vulnerability. Something that tells you if you need to do additional remediation on a machine or just update notepad++ and move on.
Edit: Found some! This is the type of info I was thinking of when I used IOCs
pez@piefed.blahaj.zoneto
Technology@lemmy.world•Notepad++ Hijacked by State-Sponsored HackersEnglish
0·4 months agoFair point. I was assuming the malicious payload would come along with an update on order to hide, but it’s also possible that the malicious payload was delivered without any update to notepad++.
I’ve not seen any IOCs published have you?
pez@piefed.blahaj.zoneto
Technology@lemmy.world•Notepad++ Hijacked by State-Sponsored HackersEnglish
0·4 months agoLooks like 8.8.1 was May 2025 https://notepad-plus-plus.org/news/v881-we-are-with-ukraine/
8.8.2 was June 2025 and has a warning to ignore “false positives” of malware in the update… Ouch. https://notepad-plus-plus.org/news/8.8.2-available-in-1-week-without-certificate/

That was no typo. Gonna use that principal like a tauntaun.