China-based espionage group compromised Notepad++ for six months
ID: 05268dd6-4bfa-5414-8142-c2b4c6fde6a1
STIX ID: report--05268dd6-4bfa-5414-8142-c2b4c6fde6a1
Feed Name: CyberScoop
A China-backed APT known as Lotus Blossom (aka Billbug/Thrip/Raspberry Typhoon) compromised Notepad++ internal systems and hijacked its updater from June–December 2025, deploying a custom backdoor and redirecting update traffic to malicious servers to conduct selective espionage. Rapid7 and the Notepad++ maintainer reported persistent access, system profiling, and remote command execution consistent with targeted long-term reconnaissance; the intrusion appears disrupted and there is no evidence of mass data exfiltration, but users are advised to update older versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
