Trusted Tool Weaponized: Lotus Blossom Hijacks Notepad++ Updates
ID: 664a15f6-41e6-550e-9c2e-22021fa4e579
STIX ID: report--664a15f6-41e6-550e-9c2e-22021fa4e579
Feed Name: securityonline.info
Unit 42 details a state-sponsored supply-chain Adversary‑in‑the‑Middle attack by Lotus Blossom (June–Dec 2025) that hijacked Notepad++ update hosting to selectively deliver malicious installers to priority targets—primarily in Southeast Asia—using DLL side‑loading to deploy a custom Chrysalis backdoor and Lua script execution to deliver Cobalt Strike Beacons; victims included government, telecom, and critical‑infrastructure organizations, and Notepad++ has since moved hosting and strengthened updater signature checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
