logo

Malicious Notepad++ Network Infrastructure

ID: f5489745-cf33-5fc0-bf0e-168fb5fdcaf4

STIX ID: report--f5489745-cf33-5fc0-bf0e-168fb5fdcaf4

Feed Name: Censys Blog

Threat Score
88/100

Date Published: 2026-02-03

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

**Executive summary:** This Censys analysis maps network-level artifacts, TLS certificate pivots, and host timelines tied to the Chrysalis backdoor campaign—linked by Rapid7 to the Lotus Blossom APT and a Notepad++ supply-chain compromise—documenting Cobalt Strike listeners, loader hashes, multiple IPs and certificates, and a timeline of activity from early 2025 through early 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.