Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used
ID: 4f26ebae-fded-57d9-ba59-806b65018ac5
STIX ID: report--4f26ebae-fded-57d9-ba59-806b65018ac5
Feed Name: cybersecurityNews.com
**Executive Summary:** A Lotus Blossom (Billbug) espionage campaign compromised Notepad++ infrastructure to distribute an NSIS installer (update.exe) that sideloaded a malicious log.dll, deploying the Chrysalis backdoor which uses custom encryption, API hashing, HTTPS C2 (api.skycloudcenter.com), and advanced loaders (including a Microsoft Warbird-based variant) to target government, telecommunications, aviation, and critical infrastructure across Southeast Asia and Central America; the report provides file and network IoCs, MITRE ATT&CK mappings, and forensic details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
