Kaspersky’s Global Research and Analysis Team (GReAT) has uncovered a sophisticated Notepad++ supply chain compromise that targeted organizations across Asia and Latin America, revealing critical security risks for Middle East governments, financial institutions, and service providers relying on widely used software tools.
The Notepad++ supply chain attack demonstrates how attackers can exploit trusted software update ‘ mechanisms to infiltrate high-value targets. GReAT researchers discovered that threat actors targeted a government organization in the Philippines, a financial institution in El Salvador, an IT service provider in Vietnam, and individuals across three countries using at least three distinct infection chains—two of which remained unknown to the public until now.
Sophisticated Attack Evolution Over Four Months
Between July and October 2025, the attackers demonstrated remarkable operational security by completely overhauling their malware, command-and-control infrastructure, and delivery methods approximately every month. This constant evolution made detection significantly more challenging for security teams relying on traditional indicators of compromise.
The Notepad++ developers disclosed on February 2, 2026, that their update infrastructure had been compromised due to a hosting provider incident. However, previous public reporting focused exclusively on malware observed in October 2025, leaving organizations unaware of the entirely different indicators used from July through September.
Multiple Infection Chains Discovered
Each attack chain employed different malicious IP addresses, domain names, execution methods, and payloads. Organizations that scanned only for the October indicators may have missed earlier infections entirely. Kaspersky solutions successfully blocked all identified attacks as they occurred, protecting customers from compromise.
Defenders who checked their systems against the publicly known IoCs and found nothing should not assume they’re in the clear. The July-September infrastructure was completely different—different IPs, different domains, different file hashes. And given how frequently these attackers rotated their tooling, we cannot rule out the existence of additional, as-yet-undiscovered chains.
Georgy Kucherin, Senior Security Researcher at Kaspersky GReAT
Implications for Middle East Organizations
While confirmed victims were located outside the Middle East, the campaign’s characteristics mirror threat models facing regional governments, banks, and critical service providers. The region’s heavy reliance on widely used developer and IT administration tools, combined with accelerated digital transformation initiatives, makes similar supply chain attacks both plausible and difficult to detect.
For Middle East organizations, this campaign serves as a critical warning that geographically distant incidents can expose blind spots in software trust, update verification, and long-term threat hunting capabilities. Kaspersky experts emphasize the importance of comprehensive security monitoring that extends beyond publicly disclosed indicators.
Comprehensive Threat Intelligence Released
Kaspersky GReAT has published the complete list of indicators of compromise, including six malicious updater hashes, 14 command-and-control URLs, and eight malicious file hashes not previously reported. The full IoC list and detailed technical analysis are available on Securelist, enabling security teams worldwide to conduct thorough retrospective investigations.
Organizations using Notepad++ or similar widely deployed software tools should immediately review their systems against the newly disclosed indicators and implement enhanced monitoring for software update processes to prevent future supply chain compromises.





