logo

China-based espionage group compromised Notepad++ for six months

ID: 05268dd6-4bfa-5414-8142-c2b4c6fde6a1

STIX ID: report--05268dd6-4bfa-5414-8142-c2b4c6fde6a1

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2026-02-02

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

A China-backed APT known as Lotus Blossom (aka Billbug/Thrip/Raspberry Typhoon) compromised Notepad++ internal systems and hijacked its updater from June–December 2025, deploying a custom backdoor and redirecting update traffic to malicious servers to conduct selective espionage. Rapid7 and the Notepad++ maintainer reported persistent access, system profiling, and remote command execution consistent with targeted long-term reconnaissance; the intrusion appears disrupted and there is no evidence of mass data exfiltration, but users are advised to update older versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.