logo

Notepad++ Attack Breakdown Reveals Sophisticated Malware and Actionable IoCs

ID: 646eabc0-3bb6-5962-8b67-56a937641253

STIX ID: report--646eabc0-3bb6-5962-8b67-56a937641253

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-02-03

Date Updated: 2026-05-22

Author: Divya

...
...

## Executive Summary: This report details a sophisticated espionage campaign attributed to Chinese APT "Lotus Blossom" that compromised Notepad++ distribution to install a custom backdoor named Chrysalis, combining DLL sideloading, custom crypto/deobfuscation, NtQuerySystemInformation abuse, and Cobalt Strike loaders; it includes command capabilities, persistence mechanisms, C2 endpoints, and a comprehensive set of file and network IoCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.