Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor
ID: 0c8c3c2f-65a9-5550-a02e-b957ce6487da
STIX ID: report--0c8c3c2f-65a9-5550-a02e-b957ce6487da
Feed Name: The Register (Security)
Security researchers attribute a trojanized Notepad++ update to the China-linked APT Lotus Blossom, who redirected update traffic to an attacker site distributing an NSIS installer containing a renamed legitimate binary (BluetoothService.exe) used for DLL sideloading and an encrypted shellcode forming the Chrysalis backdoor; Rapid7 characterizes Chrysalis as a sophisticated, persistent espionage tool with custom API hashing, obfuscation, and structured C2, and published file and network IOCs while noting attribution is based on execution-chain similarities to prior Lotus Blossom activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
