Supply Chain Attack Abused Notepad++ Update Infrastructure to Deliver Targeted Malware
ID: cff0d955-fae6-5c93-b934-e8d2b5c57860
STIX ID: report--cff0d955-fae6-5c93-b934-e8d2b5c57860
Feed Name: cybersecurityNews.com
A sophisticated supply-chain campaign compromised Notepad++'s update mechanism (June–Dec 2025), enabling attackers to distribute malicious NSIS installers that executed reconnaissance, downloaded Metasploit/Cobalt Strike payloads, and ultimately deployed a custom Chrysalis backdoor; the intrusion impacted a limited set of individual and organizational victims across multiple countries and featured rotated C2 infrastructure and multiple infection chains, while security vendors successfully blocked observed activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
