Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556) — Threadlinqs Intelligence
As of 2026-05-30, Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556) is a critical-severity supply chain threat attributed to Lotus Blossom (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 38 indicators of compromise.
Threat ID: TL-2026-0214 · Severity: CRITICAL · Status: PATCHED · Category: SUPPLY_CHAIN
Attribution: Lotus Blossom · China · ESPIONAGE
Chinese state-sponsored group Lotus Blossom (Spring Dragon) compromised Notepad++ update infrastructure from June to December 2025 to deliver the previously undocumented Chrysalis backdoor and Cobalt
Between June and December 2025, the Chinese state-sponsored advanced persistent threat group Lotus Blossom (also tracked as Spring Dragon, Billbug, Thrip, Lotus Panda, and Raspberry Typhoon) conducted a sophisticated supply chain attack by compromising the hosting infrastructure used to distribute updates for Notepad++, one of the most widely used open-source text editors globally.
The attackers gained access to the hosting provider's server managing Notepad++ updates and selectively redirected update traffic for targeted users to attacker-controlled servers. Rather than conducting a mass compromise, the group employed surgical targeting — intercepting update requests from specific IP ranges or organizational networks and serving trojanized NSIS installers (update.exe) while allowing other users to receive legitimate updates unmodified.
Three distinct infection chains were identified:
Chain 1 (Cobalt Strike via Lua Injection): The malicious NSIS installer executes a compiled Lua script (alien.ini) that injects shellcode via the EnumWindowStationsW API, ultimately deploying a Cobalt Strike HTTPS Beacon for command-and-control operations. Artifacts are staged in %appdata%\Adobe\Scripts\.
Chain 2 (ProShow DLL Sideloading): A legitimate but vulnerable ProShow executable is dropped and used to sideload a malicious DLL, establishing persistence and delivering secondary payloads. Artifacts are staged in %appdata%\ProShow\.
Chain 3 (Chrysalis Backdoor via Bluetooth DLL Sideloading): The NSIS installer drops BluetoothService.exe (a renamed legitimate Bitdefender Submission Wizard binary) alongside a malicious log.dll. When BluetoothService.exe calls the exported functions LogInit and LogWrite, log.dll loads an encrypted shellcode blob, decrypts it using the XOR key 'CRAZY', and executes the Chrysalis backdoor. The backdoor creates a hidden directory at %appdata%\Bluetooth\ and establishes persistence via Windows services (T1543.003) and registry run keys (T1547.001).
The Chrysalis backdoor represents a significant evolution in Lotus Blossom's capabilities. It features custom API hashing using FNV-1a constants (base 0x811C9DC5, prime 0x1000193), RC4 encryption for configuration data (key: qwhvb^435h&*7) and C2 response decryption (key: vAuig34%^325hGV), and integration with Microsoft Warbird — an undocumented code protection framework — to cloak malicious shellcode via NtQuerySystemInformation with the SystemCodeFlowTransition operation (WbHeapExecuteCall). The backdoor supports a comprehensive command set including interactive shell access, file operations, process creation, drive enumeration, and data exfiltration over encrypted HTTPS channels.
C2 infrastructure was rotated throughout the campaign across multiple servers: 59.110.7.32:8880, 124.222.137.114:9999, api.skycloudcenter.com, and api.wiresguard.com. Additional infrastructure included domains cdncheck.it.com, safe-dns.it.com, and self-dns.it.com for payload staging and DNS-based communication. Data exfiltration was observed via temp.sh file upload service.
The vulnerability was assigned CVE-2025-15556 (CWE-494: Download of Code Without Integrity Check) reflecting the absence of cryptographic signature validation in the WinGUp update mechanism. Notepad++ released version 8.9.1 with XML signature validation (XMLDSig) and plans for enhanced signing enforcement in version 8.9.2.
Attribution to Lotus Blossom is assessed with high confidence based on infrastructure overlap with previously documented campaigns, the group's established use of DLL sideloading techniques, targeting patterns consistent with Chinese state espionage interests in Southeast Asian government and telecommunications sectors, and code-level similarities between the Chrysalis backdoor and the group's previously documented Sagerunex implant family.
Target sectors: government, telecommunications, aviation, energy, financial, manufacturing, software-development, cloud-hosting, critical-infrastructure, defense
Target regions: Southeast Asia, South America, North America, Europe, Australia, Philippines, Vietnam, El Salvador
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 38 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, CVE-2025-15556, T1195, T1204, T1059, T1059, T1106, T1547, T1543, T1574, T1134, T1574