What to Know About the Notepad++ Supply-Chain Attack
ID: bc93ed9a-deb6-56bf-8cf4-b2b692b67f78
STIX ID: report--bc93ed9a-deb6-56bf-8cf4-b2b692b67f78
Feed Name: Security Boulevard
A critical Notepad++ updater flaw (CVE-2025-15556) stemming from a hosting provider compromise enabled the Chinese state-sponsored “Lotus Blossom” campaign to intercept update traffic and deliver trojanized installers via MitM/DNS poisoning from July–October 2025. Across three attack chains, adversaries used NSIS-based update.exe payloads to deploy Cobalt Strike beacons and the Chrysalis backdoor, achieving persistence and C2 in government, telecom, critical infrastructure, and financial sectors. The report maps TTPs to MITRE ATT&CK and recommends immediate updates to v8.9.1+, auditing persistence paths, and strengthening network/endpoint defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
