Nation-State Actors Exploit Notepad++ Supply Chain
ID: 594b253a-5ef9-50a4-ace8-b7eb9f5050d5
STIX ID: report--594b253a-5ef9-50a4-ace8-b7eb9f5050d5
Feed Name: Palo Alto Networks Unit 42
**Executive summary:** Between June and December 2025, a state‑sponsored group known as Lotus Blossom compromised Notepad++'s update infrastructure to selectively serve malicious update manifests to high‑value targets (notably system administrators) across multiple regions and sectors, resulting in delivery of the Chrysalis backdoor (via Bitdefender DLL sideloading) and Cobalt Strike beacons (via malicious Lua scripts); the report provides IoCs, detection queries, timelines, and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
