Notepad++ infrastructure hack likely tied to China-nexus APT Lotus Blossom
ID: bc6fc8ad-fd80-58f9-a971-74a828caa58c
STIX ID: report--bc6fc8ad-fd80-58f9-a971-74a828caa58c
Feed Name: Security Affairs
Rapid7 and Notepad++ maintainers report a hosting-provider compromise attributed to China-linked APT Lotus Blossom that intercepted and redirected Notepad++ update traffic from June–December 2025 to deliver a previously undocumented backdoor named 'Chrysalis'; the attack used an NSIS installer, DLL sideloading via a renamed Bitdefender Submission Wizard, and multi-stage loaders (including Warbird, Metasploit shellcode and Cobalt Strike), enabling full remote control and targeted espionage, while the hosting provider later remediated affected servers and rotated credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
