logo

Supply Chain Poison: Lotus Blossom Hits Notepad++ to Deploy “Chrysalis”

ID: d85edd16-c041-58a2-8ba3-928ab15e8260

STIX ID: report--d85edd16-c041-58a2-8ba3-928ab15e8260

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-02-05

Date Updated: 2026-04-23

Author: Ddos

...
...

Rapid7 analysis describes Lotus Blossom (a Chinese state-linked APT) performing a supply-chain compromise of the Notepad++ infrastructure to deploy a new backdoor named Chrysalis. The attackers used a Warbird-protected loader (ConsoleApplication2.exe), DLL side-loading, custom loaders, and blended commodity tooling (Cobalt Strike, Metasploit) to increase stealth and resilience; Rapid7 attributes the activity to Lotus Blossom with moderate confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.