Malicious Notepad++ Network Infrastructure
ID: f5489745-cf33-5fc0-bf0e-168fb5fdcaf4
STIX ID: report--f5489745-cf33-5fc0-bf0e-168fb5fdcaf4
Feed Name: Censys Blog
Threat Score
Date Published: 2026-02-03
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
...
...
**Executive summary:** This Censys analysis maps network-level artifacts, TLS certificate pivots, and host timelines tied to the Chrysalis backdoor campaign—linked by Rapid7 to the Lotus Blossom APT and a Notepad++ supply-chain compromise—documenting Cobalt Strike listeners, loader hashes, multiple IPs and certificates, and a timeline of activity from early 2025 through early 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
