Lotus Blossom Hackers Breach Official Notepad++ Hosting Infrastructure
ID: 6f586efa-b79e-55a3-9e5e-db0311c019b5
STIX ID: report--6f586efa-b79e-55a3-9e5e-db0311c019b5
Feed Name: GBHackers
Between June and December 2025, state‑sponsored actor 'Lotus Blossom' hijacked Notepad++ update hosting to redirect selected update requests to attacker servers, delivering trojanized NSIS installers (update.exe) that used WinGUp validation weaknesses, DLL sideloading and Lua scripts to install Cobalt Strike beacons and a custom Chrysalis backdoor against government, telecom, cloud, energy, financial, manufacturing and software targets; Notepad++ has released mitigations (8.8.9/8.9.1+) and users should manually update from official sources and monitor for anomalous gup.exe/update.exe activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
