logo

Notepad++ infrastructure hack likely tied to China-nexus APT Lotus Blossom

ID: bc6fc8ad-fd80-58f9-a971-74a828caa58c

STIX ID: report--bc6fc8ad-fd80-58f9-a971-74a828caa58c

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Rapid7 and Notepad++ maintainers report a hosting-provider compromise attributed to China-linked APT Lotus Blossom that intercepted and redirected Notepad++ update traffic from June–December 2025 to deliver a previously undocumented backdoor named 'Chrysalis'; the attack used an NSIS installer, DLL sideloading via a renamed Bitdefender Submission Wizard, and multi-stage loaders (including Warbird, Metasploit shellcode and Cobalt Strike), enabling full remote control and targeted espionage, while the hosting provider later remediated affected servers and rotated credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.