Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder
ID: a802a7c3-1135-5f98-b817-c9e900a4737e
STIX ID: report--a802a7c3-1135-5f98-b817-c9e900a4737e
Feed Name: Elastic Security Labs
Threat Score
Lotus Blossom (state-sponsored) executed a supply-chain compromise of Notepad++ updates that deployed the Chrysalis backdoor — a feature-rich implant using DLL sideloading, reflective loading, API-hashing, and DNS beaconing — and this report demonstrates detection and automated response using Elastic Security's Attack Discovery, Workflows, and Agent Builder to rapidly confirm, triage, and remediate infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
