Lotus Blossom Hacking Group Breaches Notepad++ Hosting Infrastructure
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The recent breach of Notepad++ hosting infrastructure is attributed to the China-linked Lotus Blossom hacking group. This incident enabled the group to deliver a previously undocumented backdoor, codenamed Chrysalis, to users of the popular open-source text editor. The compromise began in June 2025, when threat actors hijacked update traffic due to insufficient verification controls in older Notepad++ versions. The attack continued until December 2, 2025, when the attackers’ access was terminated.
Notepad++ maintainer Don Ho confirmed that the breach allowed malicious servers to serve tampered updates to certain users. Rapid7’s analysis found that the malware was delivered through an installer named update.exe, which was downloaded from a specific IP address. This installer contained multiple components, including a malicious DLL and encrypted shellcode.
Chrysalis is designed to gather system information and connect to an external server for additional commands. Although the command-and-control server is currently offline, the malware has capabilities for file operations and process creation, indicating a sophisticated level of development.
Rapid7’s findings suggest that the Lotus Blossom group has evolved its tactics, employing techniques like DLL side-loading and service persistence. The integration of custom malware alongside established frameworks like Metasploit and Cobalt Strike shows a strategic adaptation to evade detection.
Implications for Users and Organizations
This breach serves as a critical reminder of the vulnerabilities associated with open-source software and the importance of robust update verification processes. Users should be vigilant about the sources of their software updates and ensure they are using the latest versions with security patches.
Organizations relying on open-source tools must implement stringent security measures, including regular audits of their update mechanisms and monitoring for unusual activity. The incident underscores the need for heightened awareness of potential threats from state-sponsored actors.
As cyber threats continue to evolve, it is essential for users and organizations to stay informed about the latest tactics employed by threat actors like Lotus Blossom. This includes understanding the risks associated with software updates and the potential for malware delivery through compromised infrastructure.
Key Takeaways
- Regularly update Notepad++ to the latest version to ensure you have the latest security patches.
- Verify the source of software updates to avoid tampered installations.
- Monitor your system for unusual activity, especially after software updates.
- Implement security measures such as firewalls and antivirus software to protect against malware.
- Educate your team about the risks of using open-source software and the importance of security hygiene.
Key Terms & Concepts
- Chrysalis: In this article, Chrysalis refers to a backdoor malware delivered to Notepad++ users by the Lotus Blossom hacking group.
- DLL side-loading: DLL side-loading is a technique used by attackers to exploit legitimate software to run malicious code.
- Cobalt Strike: Cobalt Strike is a legitimate penetration testing tool often misused by threat actors for malicious purposes.
- command-and-control server: A command-and-control server is a remote server used by attackers to send commands to compromised systems.
- update verification controls: Update verification controls are security measures that ensure software updates are authentic and have not been tampered with.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.