logo

Lotus Blossom Hackers Breach Official Notepad++ Hosting Infrastructure

ID: 6f586efa-b79e-55a3-9e5e-db0311c019b5

STIX ID: report--6f586efa-b79e-55a3-9e5e-db0311c019b5

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Between June and December 2025, state‑sponsored actor 'Lotus Blossom' hijacked Notepad++ update hosting to redirect selected update requests to attacker servers, delivering trojanized NSIS installers (update.exe) that used WinGUp validation weaknesses, DLL sideloading and Lua scripts to install Cobalt Strike beacons and a custom Chrysalis backdoor against government, telecom, cloud, energy, financial, manufacturing and software targets; Notepad++ has released mitigations (8.8.9/8.9.1+) and users should manually update from official sources and monitor for anomalous gup.exe/update.exe activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.