1 of 1
Story summary
- Black Cat conducted an SEO poisoning campaign that compromised 277,800 hosts in China from December 7 to 20, 2025 by creating fake Notepad++ download sites to lure users into a backdoor Trojan.
- The backdoor Trojan silently collects data by contacting a server after installation, showing a shift to manipulated search results as an attack vector.
- Black Cat has been active since at least 2022 and previously stole $160,000 in cryptocurrency.
