Threat reportSupply ChainTL-2026-0214

Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556)

criticalPATCHED

Lotus Blossom APT Supply Chain Compromise of Notepad++ (TL-2026-0214), also tracked as Notepad++ Supply Chain Attack, is a critical-severity supply-chain compromise, first published 2026-03-12. It is attributed to Lotus Blossom (China) with high confidence, affects Notepad++ Notepad++, references 1 CVE (CVE-2025-15556), maps to 27 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 38 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
27MITRE ATT&CK
Actors
1Lotus Blossom
Detection rules
9SPL · KQL · Sigma
IOCs
38Indicators of compromise

Key facts for TL-2026-0214

Threat ID
TL-2026-0214
Also known as
Notepad++ Supply Chain Attack, Operation Chrysalis
Severity
CRITICAL
Status
PATCHED
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
Lotus Blossom
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government, telecommunications, aviation, energy, financial, manufacturing, software-development, cloud-hosting, critical-infrastructure, defense
Target regions
Southeast Asia, South America, North America, Europe, Australia, Philippines, Vietnam, El Salvador
Detection rules
9
Indicators of compromise
38

Malware and tooling in Lotus Blossom APT Supply Chain Compromise of Notepad++

Malware and tooling: Chrysalis, Cobalt Strike, metasploit

How Lotus Blossom APT Supply Chain Compromise of Notepad++ works

Chinese state-sponsored group Lotus Blossom (Spring Dragon) compromised Notepad++ update infrastructure from June to December 2025 to deliver the previously undocumented Chrysalis backdoor and Cobalt Strike Beacon via trojanized NSIS installers. The campaign targeted government, telecommunications, aviation, energy, and software development organizations across Southeast Asia, South America, the United States, and Europe for espionage and persistent network access.

Between June and December 2025, the Chinese state-sponsored advanced persistent threat group Lotus Blossom (also tracked as Spring Dragon, Billbug, Thrip, Lotus Panda, and Raspberry Typhoon) conducted a sophisticated supply chain attack by compromising the hosting infrastructure used to distribute updates for Notepad++, one of the most widely used open-source text editors globally.

The attackers gained access to the hosting provider's server managing Notepad++ updates and selectively redirected update traffic for targeted users to attacker-controlled servers. Rather than conducting a mass compromise, the group employed surgical targeting — intercepting update requests from specific IP ranges or organizational networks and serving trojanized NSIS installers (update.exe) while allowing other users to receive legitimate updates unmodified.

Three distinct infection chains were identified:

Chain 1 (Cobalt Strike via Lua Injection): The malicious NSIS installer executes a compiled Lua script (alien.ini) that injects shellcode via the EnumWindowStationsW API, ultimately deploying a Cobalt Strike HTTPS Beacon for command-and-control operations. Artifacts are staged in %appdata%\Adobe\Scripts\.

Chain 2 (ProShow DLL Sideloading): A legitimate but vulnerable ProShow executable is dropped and used to sideload a malicious DLL, establishing persistence and delivering secondary payloads. Artifacts are staged in %appdata%\ProShow\.

Chain 3 (Chrysalis Backdoor via Bluetooth DLL Sideloading): The NSIS installer drops BluetoothService.exe (a renamed legitimate Bitdefender Submission Wizard binary) alongside a malicious log.dll. When BluetoothService.exe calls the exported functions LogInit and LogWrite, log.dll loads an encrypted shellcode blob, decrypts it using the XOR key 'CRAZY', and executes the Chrysalis backdoor. The backdoor creates a hidden directory at %appdata%\Bluetooth\ and establishes persistence via Windows services (T1543.003) and registry run keys (T1547.001).

The Chrysalis backdoor represents a significant evolution in Lotus Blossom's capabilities. It features custom API hashing using FNV-1a constants (base 0x811C9DC5, prime 0x1000193), RC4 encryption for configuration data (key: qwhvb^435h&*7) and C2 response decryption (key: vAuig34%^325hGV), and integration with Microsoft Warbird — an undocumented code protection framework — to cloak malicious shellcode via NtQuerySystemInformation with the SystemCodeFlowTransition operation (WbHeapExecuteCall). The backdoor supports a comprehensive command set including interactive shell access, file operations, process creation, drive enumeration, and data exfiltration over encrypted HTTPS channels.

C2 infrastructure was rotated throughout the campaign across multiple servers: 59.110.7.32:8880, 124.222.137.114:9999, api.skycloudcenter.com, and api.wiresguard.com. Additional infrastructure included domains cdncheck.it.com, safe-dns.it.com, and self-dns.it.com for payload staging and DNS-based communication. Data exfiltration was observed via temp.sh file upload service.

The vulnerability was assigned CVE-2025-15556 (CWE-494: Download of Code Without Integrity Check) reflecting the absence of cryptographic signature validation in the WinGUp update mechanism. Notepad++ released version 8.9.1 with XML signature validation (XMLDSig) and plans for enhanced signing enforcement in version 8.9.2.

Attribution to Lotus Blossom is assessed with high confidence based on infrastructure overlap with previously documented campaigns, the group's established use of DLL sideloading techniques, targeting patterns consistent with Chinese state espionage interests in Southeast Asian government and telecommunications sectors, and code-level similarities between the Chrysalis backdoor and the group's previously documented Sagerunex implant family.

MITRE ATT&CK techniques used in TL-2026-0214

collection

T1005 Data from Local System; T1074 Data Staged

discovery

T1016 System Network Configuration Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1134 Access Token Manipulation; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1620 Reflective Code Loading

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

initial-access

T1195 Supply Chain Compromise

persistence

T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

stealth

T1574 Hijack Execution Flow

Affected products and versions in Lotus Blossom APT Supply Chain Compromise of Notepad++

  • Notepad++ — Notepad++
    Vulnerable versions: 8.9 and earlier
    Fixed in: 8.9.1 (XMLDSig validation); 8.9.2 (enhanced signing enforcement)
  • Notepad++ — WinGUp (Generic Updater)
    Vulnerable versions: All versions prior to 8.9.1 update
    Fixed in: Patched in 8.9.1 with certificate/signature verification

Remediation for Lotus Blossom APT Supply Chain Compromise of Notepad++

Patches

  • Notepad++ 8.9.1 — adds XMLDSig signature validation for updates
  • Notepad++ 8.9.2 — enhanced signing enforcement (upcoming)

Immediate actions

  • Update Notepad++ to version 8.9.1 or later manually — do NOT use the built-in updater on older versions
  • Block known C2 IPs at perimeter: 95.179.213.0, 45.76.155.202, 45.32.144.255, 45.77.31.210, 61.4.102.97, 59.110.7.32, 124.222.137.114
  • Block known C2 domains: api.skycloudcenter.com, api.wiresguard.com, cdncheck.it.com, safe-dns.it.com, self-dns.it.com
  • Hunt for Global\Jdhfv_1.0.1 mutex creation events across endpoints
  • Search for BluetoothService.exe or log.dll in %appdata%\Bluetooth\ directories
  • Monitor for gup.exe (Notepad++ updater) spawning unusual child processes

Workarounds

  • Disable automatic updates in Notepad++ and apply updates manually from verified sources
  • Block execution of gup.exe via application control policies until updated
  • Use network-level controls to block access to Notepad++ update servers from sensitive environments

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL sideloading and shellcode injection
  • Implement application allowlisting to prevent renamed legitimate binaries from executing
  • Enforce software update signature validation across all third-party applications
  • Segment networks to limit lateral movement from compromised developer workstations
  • Monitor for Cobalt Strike Beacon traffic patterns on egress
  • Implement DNS sinkholing for known Lotus Blossom infrastructure domains

CVEs associated with Lotus Blossom APT Supply Chain Compromise of Notepad++

CVE-2025-15556

Weaknesses (CWE) in Lotus Blossom APT Supply Chain Compromise of Notepad++

CWE-494

Timeline of Lotus Blossom APT Supply Chain Compromise of Notepad++

  • Lotus Blossom gains initial access to Notepad++ hosting provider infrastructure, beginning the supply chain compromise
  • Attackers begin selectively redirecting Notepad++ update traffic to attacker-controlled servers delivering trojanized NSIS installers
  • C2 communication observed to 45.76.155.202 for Cobalt Strike Beacon delivery via Lua script injection chain
  • C2 infrastructure shifted to 45.77.31.210; Lua script injection variant and EnumWindowStationsW API exploitation observed
  • Chrysalis backdoor deployment via BluetoothService.exe DLL sideloading chain begins targeting organizations in Southeast Asia and South America
  • October variant shifts to DLL sideloading via renamed Bitdefender utility (BluetoothService.exe) loading malicious log.dll with XOR-encrypted shellcode
  • Active payload delivery from compromised infrastructure ceases
  • Hosting provider reports attacker credential-based redirection access terminated
  • Notepad++ creator Don Ho alerts users to traffic hijacking incidents affecting update infrastructure
  • Rapid7 publishes full technical analysis of Chrysalis backdoor and Lotus Blossom attribution; CVE-2025-15556 assigned
  • IOC repository published on GitHub with Falcon LogScale queries, YARA/Sigma rules, and MITRE ATT&CK mappings
  • Notepad++ 8.9.1 released with XMLDSig signature validation for update mechanism
  • Palo Alto Unit 42 publishes expanded analysis identifying additional infrastructure and targets in US and European organizations
  • ASEC AhnLab includes Lotus Blossom Notepad++ campaign in February 2026 APT Group Trend Report
  • As of 2026-05-29, CVE-2025-15556 is patched (Notepad++ v8.8.9 added signature verification; v8.9.2 adds XMLDSig) and is in CISA KEV, while the Lotus Blossom campaign concluded after access ended ~Dec 2 2025 with infra dead and no ongoing exploitation reported. The actor stays active broadly, but this specific campaign is over and remediated.

Sources cited for Lotus Blossom APT Supply Chain Compromise of Notepad++

Detection coverage for TL-2026-0214

As of 2026-03-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0214 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
38 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats