Attack Methodology
The attackers manipulate search engine rankings on platforms such as Microsoft Bing, ensuring that malicious websites appear prominently in searches for popular and legitimate software applications. Victims who access these poisoned search results are presented with professionally crafted download pages that mimic authentic software portals while delivering trojanized installation packages containing embedded malicious components.
Once executed, the installer silently deploys a backdoor trojan that operates without user visibility, enabling unauthorized extraction of sensitive information from the compromised host.
Threat Actor Profile
Black Cat has been active since approximately 2022 and has consistently conducted campaigns centered on data theft and remote system compromise using SEO-poisoned distribution mechanisms. Earlier activity linked to this group includes a 2023 operation involving the impersonation of AICoin, which resulted in the theft of cryptocurrency assets valued at roughly USD 160,000.
Current Campaign Infrastructure
In the most recent campaign, the threat actors registered deceptive domains crafted to lure users searching for legitimate software, particularly Notepad++. Examples include cn-notepadplusplus[.]com alongside related infrastructure such as cn-obsidian[.]com, cn-winscp[.]com, and notepadplusplus[.]cn. The consistent use of the “cn” prefix strongly suggests intentional targeting of Chinese-speaking users.
Infection Chain
When victims click download buttons on the fraudulent sites, they are redirected to a counterfeit GitHub interface hosted at github.zh-cns.top, which delivers a ZIP archive. This archive contains an installer that drops a desktop shortcut acting as a loader, abusing DLL side-loading techniques to execute a malicious library and activate the backdoor payload.
Post-Compromise Activity
Following successful execution, the backdoor initiates command-and-control communication with a hardcoded server at sbido.com:2869. Through this channel, the malware supports multiple data theft functions, including browser credential harvesting, keystroke logging, clipboard data collection, and broader system reconnaissance.
Impact Assessment
Between December 7 and December 20, 2025, CNCERT/CC and ThreatBook recorded approximately 277,800 compromised systems within China attributed to Black Cat activity, with peak infection rates reaching 62,167 hosts in a single day.
Mitigation Recommendations
Security researchers advise users to exercise caution when interacting with search engine results and to avoid downloading software from unverified or third-party websites. Software should be obtained exclusively from official vendor sources or well-established, trusted distribution channels.
The National Computer Network Emergency Response Technical Team/Coordination Center of China1 (CNCERT/CC) is National Computer Network Emergency Response Technical Team/Coordination Center of China China’s national computer security incident response team (CSIRT). It coordinates prevention, detection, warning and handling of major cybersecurity incidents on the public Internet and critical information infrastructure across the country. It also serves as a key international node in incident-response cooperation networks.
Beijing Weibu Online2 (also known as ThreatBook) is a Chinese cybersecurity company specializing in threat intelligence, network detection and response, and digital risk protection. It focuses on intelligence-driven detection to help enterprises and governments identify and respond to advanced cyber threats, especially those originating in the Asia-Pacific region.
Black Cat3 (also known as ALPHV or Noberus) is a transnational cybercrime organization and ransomware-as-a-service (RaaS) operation active since late 2021. It is regarded as one of the most sophisticated and damaging ransomware groups of the 2020s, linked to Russian-speaking cybercriminal networks and earlier crews such as DarkSide (hacker group) and BlackMatter.