Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group
ID: 13cbaf74-0e93-5aed-bdd2-c7ef9cf19fcb
STIX ID: report--13cbaf74-0e93-5aed-bdd2-c7ef9cf19fcb
Feed Name: The Hacker News
A China-linked APT (Lotus Blossom) compromised Notepad++'s hosting/update infrastructure between June and December 2025 to deliver a custom backdoor called "Chrysalis" via tampered NSIS installer updates; Rapid7 and Kaspersky analyses describe multiple targeted infection chains using DLL sideloading, Metasploit/Cobalt Strike loaders, rotating C2s and numerous IoCs, with observed victims across APAC, South America and Australia — the issue was fixed in version 8.8.9 and the project migrated hosting and rotated credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
