“Totally Unexpected” Package Malware Using Modified Notepad++ Plug-in (WikiLoader)

“Totally Unexpected” Package Malware Using Modified Notepad++ Plug-in (WikiLoader)

AhnLab SEcurity intelligence Center (ASEC) has recently identified the distribution of a modified version of “mimeTools.dll”, a default Notepad++ plug-in. The malicious mimeTools.dll file in question was included in the package installation file of a certain version of the Notepad++ package and disguised as a legitimate package file. As shown