Rapid7 Labs and the Rapid7 MDR team reported a targeted espionage campaign attributed to the Chinese APT group Lotus Blossom, in which attackers compromised infrastructure used to distribute Notepad++ and leveraged it to deliver a previously undocumented backdoor dubbed Chrysalis. Victimology described in the reporting includes government, telecom, aviation, media, and other critical infrastructure organizations, with activity historically concentrated in Southeast Asia and later observed in Central America. The intrusion chain observed on affected hosts included execution of notepad++.exe and GUP.exe followed by a suspicious update.exe downloaded from 95.179.213.0, consistent with abuse of the Notepad++ distribution channel; Rapid7 noted that while prior public reporting referenced plugin replacement and updater-related mechanisms, their forensics did not confirm a specific sub-mechanism beyond the observed execution sequence.
Technical analysis described NSIS installer-based delivery, DLL sideloading, and multiple custom loaders, including a notable loader sample (“ConsoleApplication2.exe”) that used Microsoft Warbird code-protection to obscure shellcode execution, alongside custom API-hashing and obfuscation. Rapid7 indicated the reporting includes actionable IOCs to support detection and response. Separate reporting on Pulsar RAT describes a different Windows malware campaign (persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run, PowerShell loaders, Donut shellcode injection, and Discord webhook exfiltration) and does not appear connected to the Notepad++/Chrysalis activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Rapid7 Labs and Rapid7 MDR disclosed a sophisticated intrusion they attributed with moderate confidence to the China-linked APT Lotus Blossom. The report detailed delivery of a previously undocumented backdoor named Chrysalis through abused Notepad++-related infrastructure, alongside use of Metasploit and Cobalt Strike.
The attacker's access to the compromised Notepad++ hosting infrastructure was terminated on December 2, 2025, ending the update-request hijacking that had persisted since June. Afterward, Notepad++ migrated hosting providers and rotated credentials.
Notepad++ released version 8.8.9 in December 2025 to address insufficient update verification in older versions. The weakness had enabled tampered updater flows to deliver malicious installers in the supply-chain compromise.
No payloads were detected from the campaign beginning in November 2025, indicating the malicious delivery activity had ceased by then. This marked a visible drop-off in observed exploitation before the infrastructure access was terminated.
Kaspersky observed three distinct infection chains linked to the campaign between July and October 2025, affecting a small set of victims in APAC and other regions. Reported victim sectors included telecom, government, transportation, finance, and IT services.
Infrastructure hosting Notepad++ was compromised, allowing selective redirection of some software update requests to attacker-controlled servers. Reporting indicates this malicious hijacking began in June 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourceletsdatascience.com
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.