logo

Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder

ID: 2a2497ee-a854-5659-8333-64c70cb85d7e

STIX ID: report--2a2497ee-a854-5659-8333-64c70cb85d7e

Feed Name: Elastic Security Labs

Threat Score
90/100

Date Published: 2026-02-18

Date Updated: 2026-08-27

Author: James Spiteri,Dhrumil Patel

...
...

This report documents a June–December 2025 supply-chain campaign by the China-linked APT group Lotus Blossom that hijacked Notepad++ updates to deliver the Chrysalis backdoor; Chrysalis employs DLL sideloading (via a signed Bitdefender binary), reflective DLL loading, custom hashing/encryption, API hashing for evasion and a confirmed DNS C2 (api.skycloudcenter.com). The document also demonstrates how Elastic Security’s Attack Discovery, Workflows, and Agent Builder can automatically correlate alerts, verify malware (VirusTotal), run ES|QL hunts, create cases and Slack incident channels, and initiate response actions to reduce time-to-confirmation from hours to minutes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.