logo

Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder

ID: a802a7c3-1135-5f98-b817-c9e900a4737e

STIX ID: report--a802a7c3-1135-5f98-b817-c9e900a4737e

Feed Name: Elastic Security Labs

Threat Score
90/100

Date Published: 2026-02-18

Date Updated: 2026-04-27

...
...

Lotus Blossom (state-sponsored) executed a supply-chain compromise of Notepad++ updates that deployed the Chrysalis backdoor — a feature-rich implant using DLL sideloading, reflective loading, API-hashing, and DNS beaconing — and this report demonstrates detection and automated response using Elastic Security's Attack Discovery, Workflows, and Agent Builder to rapidly confirm, triage, and remediate infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.