Google Drive Caching is a malicious browser extension used as a persistence and information-stealing component in the EmEditor supply chain compromise. In the reported attack, users who downloaded a trojanized EmEditor installer from the compromised official website received malware that executed a VBScript/PowerShell chain to fetch additional payloads in memory. The extension was then deployed to maintain unauthorized access after initial infection. Reported capabilities include collection of system information, browser history, bookmarks, cookies, and credentials; theft of browser and application credentials affecting Chrome, Edge, Brave, Opera, Discord, Slack, Zoom, Microsoft Teams, WinSCP, PuTTY, Telegram, Steam, and Zoho Mail; remote command execution; use of a domain generation algorithm for resilient command-and-control; clipboard monitoring and cryptocurrency address replacement; keylogging; and theft of Facebook advertising account credentials. The broader campaign also collected files from Desktop, Documents, and Downloads folders and VPN configurations. The malware was analyzed by Qianxin. Attribution was not established in the provided content, though researchers suggested a profit-driven motive. The attack targeted EmEditor users globally, including developers, system administrators, and other technical professionals. High-confidence infection context is the compromised EmEditor download flow, where the malicious installer was signed by WALSHAM INVESTMENTS LIMITED rather than Emurasoft Inc.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious browser extension used for persistence, credential theft, clipboard monitoring for cryptocurrency address replacement, and command-and-control via Domain Generation Algorithm. It is deployed as part of a supply chain attack on EmEditor and is capable of stealing credentials from browsers and productivity applications.
A malicious browser extension used for persistence and information stealing, capable of collecting system information, browser history, bookmarks, cookies, clipboard hijacking (for cryptocurrency theft), keylogging, and stealing Facebook ad accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.