WALSHAM
WALSHAM is a multi-stage spyware malware family delivered via a software supply-chain compromise of the EmEditor installer reported in late December 2025. Attackers hijacked the official EmEditor download flow and served a trojanized MSI package through the legitimate “Download Now” button. The modified MSI used a CustomAction to spawn PowerShell, retrieve first-stage code from EmEditorjp[.]com, and then download additional modules from EmEditorgb[.]com and EmEditorde[.]com; organizations were also advised to investigate traffic to cachingdrive[.]com. Reported capabilities include host/environment fingerprinting, geofencing, credential theft, defense evasion including disabling PowerShell ETW, and preparation for lateral movement deeper into victim networks. Execution was deferred until after installation to reduce early detection. The malware terminated in Armenia, Belarus, Georgia, Kazakhstan, and Kyrgyzstan, and reporting assessed the operators were likely of Russian or broader CIS origin based on the exclusion pattern. The campaign affected users who downloaded EmEditor from the official source, illustrating the risk to Windows organizations relying on trusted public software distribution channels.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as spyware delivered via a trojanized EmEditor installer in a supply-chain compromise; described in the broader context as a multi-stage tool capable of credential theft, defense evasion (disabling PowerShell ETW), and enabling follow-on intrusion/lateral movement.
WALSHAM is spyware that was used to compromise the official EmEditor installer, acting as an imposter to deliver malicious payloads.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.