Threat reportSupply ChainTL-2026-0214
Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556)
Lotus Blossom APT Supply Chain Compromise of Notepad++ (TL-2026-0214), also tracked as Notepad++ Supply Chain Attack, is a critical-severity supply-chain compromise, first published 2026-03-12. It is attributed to Lotus Blossom (China) with high confidence, affects Notepad++ Notepad++, references 1 CVE (CVE-2025-15556), maps to 27 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 38 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 27MITRE ATT&CK
- Actors
- 1Lotus Blossom
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 38Indicators of compromise
Key facts for TL-2026-0214
- Threat ID
- TL-2026-0214
- Also known as
- Notepad++ Supply Chain Attack, Operation Chrysalis
- Severity
- CRITICAL
- Status
- PATCHED
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Lotus Blossom
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, telecommunications, aviation, energy, financial, manufacturing, software-development, cloud-hosting, critical-infrastructure, defense
- Target regions
- Southeast Asia, South America, North America, Europe, Australia, Philippines, Vietnam, El Salvador
- Detection rules
- 9
- Indicators of compromise
- 38
Malware and tooling in Lotus Blossom APT Supply Chain Compromise of Notepad++
Malware and tooling: Chrysalis, Cobalt Strike, metasploit
How Lotus Blossom APT Supply Chain Compromise of Notepad++ works
Chinese state-sponsored group Lotus Blossom (Spring Dragon) compromised Notepad++ update infrastructure from June to December 2025 to deliver the previously undocumented Chrysalis backdoor and Cobalt Strike Beacon via trojanized NSIS installers. The campaign targeted government, telecommunications, aviation, energy, and software development organizations across Southeast Asia, South America, the United States, and Europe for espionage and persistent network access.
Between June and December 2025, the Chinese state-sponsored advanced persistent threat group Lotus Blossom (also tracked as Spring Dragon, Billbug, Thrip, Lotus Panda, and Raspberry Typhoon) conducted a sophisticated supply chain attack by compromising the hosting infrastructure used to distribute updates for Notepad++, one of the most widely used open-source text editors globally.
The attackers gained access to the hosting provider's server managing Notepad++ updates and selectively redirected update traffic for targeted users to attacker-controlled servers. Rather than conducting a mass compromise, the group employed surgical targeting — intercepting update requests from specific IP ranges or organizational networks and serving trojanized NSIS installers (update.exe) while allowing other users to receive legitimate updates unmodified.
Three distinct infection chains were identified:
Chain 1 (Cobalt Strike via Lua Injection): The malicious NSIS installer executes a compiled Lua script (alien.ini) that injects shellcode via the EnumWindowStationsW API, ultimately deploying a Cobalt Strike HTTPS Beacon for command-and-control operations. Artifacts are staged in %appdata%\Adobe\Scripts\.
Chain 2 (ProShow DLL Sideloading): A legitimate but vulnerable ProShow executable is dropped and used to sideload a malicious DLL, establishing persistence and delivering secondary payloads. Artifacts are staged in %appdata%\ProShow\.
Chain 3 (Chrysalis Backdoor via Bluetooth DLL Sideloading): The NSIS installer drops BluetoothService.exe (a renamed legitimate Bitdefender Submission Wizard binary) alongside a malicious log.dll. When BluetoothService.exe calls the exported functions LogInit and LogWrite, log.dll loads an encrypted shellcode blob, decrypts it using the XOR key 'CRAZY', and executes the Chrysalis backdoor. The backdoor creates a hidden directory at %appdata%\Bluetooth\ and establishes persistence via Windows services (T1543.003) and registry run keys (T1547.001).
The Chrysalis backdoor represents a significant evolution in Lotus Blossom's capabilities. It features custom API hashing using FNV-1a constants (base 0x811C9DC5, prime 0x1000193), RC4 encryption for configuration data (key: qwhvb^435h&*7) and C2 response decryption (key: vAuig34%^325hGV), and integration with Microsoft Warbird — an undocumented code protection framework — to cloak malicious shellcode via NtQuerySystemInformation with the SystemCodeFlowTransition operation (WbHeapExecuteCall). The backdoor supports a comprehensive command set including interactive shell access, file operations, process creation, drive enumeration, and data exfiltration over encrypted HTTPS channels.
C2 infrastructure was rotated throughout the campaign across multiple servers: 59.110.7.32:8880, 124.222.137.114:9999, api.skycloudcenter.com, and api.wiresguard.com. Additional infrastructure included domains cdncheck.it.com, safe-dns.it.com, and self-dns.it.com for payload staging and DNS-based communication. Data exfiltration was observed via temp.sh file upload service.
The vulnerability was assigned CVE-2025-15556 (CWE-494: Download of Code Without Integrity Check) reflecting the absence of cryptographic signature validation in the WinGUp update mechanism. Notepad++ released version 8.9.1 with XML signature validation (XMLDSig) and plans for enhanced signing enforcement in version 8.9.2.
Attribution to Lotus Blossom is assessed with high confidence based on infrastructure overlap with previously documented campaigns, the group's established use of DLL sideloading techniques, targeting patterns consistent with Chinese state espionage interests in Southeast Asian government and telecommunications sectors, and code-level similarities between the Chrysalis backdoor and the group's previously documented Sagerunex implant family.
MITRE ATT&CK techniques used in TL-2026-0214
collection
T1005 Data from Local System; T1074 Data Staged
discovery
T1016 System Network Configuration Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1134 Access Token Manipulation; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1620 Reflective Code Loading
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
initial-access
persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
stealth
Affected products and versions in Lotus Blossom APT Supply Chain Compromise of Notepad++
Remediation for Lotus Blossom APT Supply Chain Compromise of Notepad++
Patches
- Notepad++ 8.9.1 — adds XMLDSig signature validation for updates
- Notepad++ 8.9.2 — enhanced signing enforcement (upcoming)
Immediate actions
- Update Notepad++ to version 8.9.1 or later manually — do NOT use the built-in updater on older versions
- Block known C2 IPs at perimeter: 95.179.213.0, 45.76.155.202, 45.32.144.255, 45.77.31.210, 61.4.102.97, 59.110.7.32, 124.222.137.114
- Block known C2 domains: api.skycloudcenter.com, api.wiresguard.com, cdncheck.it.com, safe-dns.it.com, self-dns.it.com
- Hunt for Global\Jdhfv_1.0.1 mutex creation events across endpoints
- Search for BluetoothService.exe or log.dll in %appdata%\Bluetooth\ directories
- Monitor for gup.exe (Notepad++ updater) spawning unusual child processes
Workarounds
- Disable automatic updates in Notepad++ and apply updates manually from verified sources
- Block execution of gup.exe via application control policies until updated
- Use network-level controls to block access to Notepad++ update servers from sensitive environments
Longer-term hardening
- Deploy EDR with behavioral detection for DLL sideloading and shellcode injection
- Implement application allowlisting to prevent renamed legitimate binaries from executing
- Enforce software update signature validation across all third-party applications
- Segment networks to limit lateral movement from compromised developer workstations
- Monitor for Cobalt Strike Beacon traffic patterns on egress
- Implement DNS sinkholing for known Lotus Blossom infrastructure domains
CVEs associated with Lotus Blossom APT Supply Chain Compromise of Notepad++
Weaknesses (CWE) in Lotus Blossom APT Supply Chain Compromise of Notepad++
Timeline of Lotus Blossom APT Supply Chain Compromise of Notepad++
- Lotus Blossom gains initial access to Notepad++ hosting provider infrastructure, beginning the supply chain compromise
- Attackers begin selectively redirecting Notepad++ update traffic to attacker-controlled servers delivering trojanized NSIS installers
- C2 communication observed to 45.76.155.202 for Cobalt Strike Beacon delivery via Lua script injection chain
- C2 infrastructure shifted to 45.77.31.210; Lua script injection variant and EnumWindowStationsW API exploitation observed
- Chrysalis backdoor deployment via BluetoothService.exe DLL sideloading chain begins targeting organizations in Southeast Asia and South America
- October variant shifts to DLL sideloading via renamed Bitdefender utility (BluetoothService.exe) loading malicious log.dll with XOR-encrypted shellcode
- Active payload delivery from compromised infrastructure ceases
- Hosting provider reports attacker credential-based redirection access terminated
- Notepad++ creator Don Ho alerts users to traffic hijacking incidents affecting update infrastructure
- Rapid7 publishes full technical analysis of Chrysalis backdoor and Lotus Blossom attribution; CVE-2025-15556 assigned
- IOC repository published on GitHub with Falcon LogScale queries, YARA/Sigma rules, and MITRE ATT&CK mappings
- Notepad++ 8.9.1 released with XMLDSig signature validation for update mechanism
- Palo Alto Unit 42 publishes expanded analysis identifying additional infrastructure and targets in US and European organizations
- ASEC AhnLab includes Lotus Blossom Notepad++ campaign in February 2026 APT Group Trend Report
- As of 2026-05-29, CVE-2025-15556 is patched (Notepad++ v8.8.9 added signature verification; v8.9.2 adds XMLDSig) and is in CISA KEV, while the Lotus Blossom campaign concluded after access ended ~Dec 2 2025 with infra dead and no ongoing exploitation reported. The actor stays active broadly, but this specific campaign is over and remediated.
Sources cited for Lotus Blossom APT Supply Chain Compromise of Notepad++
- Rapid7 — The Chrysalis Backdoor: A Deep Dive into Lotus Blossom's Toolkit
- Palo Alto Unit 42 — Nation-State Actors Exploit Notepad++ Supply Chain
- The Hacker News — Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom
- Tenable — FAQ: Notepad++ Supply Chain Compromise
- Help Net Security — Notepad++ Supply Chain Attack: IOCs and Targets
- The Register — Notepad++ Hijacking Linked to Chinese Lotus Blossom Crew
- SOCRadar — Notepad++ Infrastructure Hijacked in State-Linked Supply Chain Attack
- Security Affairs — Notepad++ Infrastructure Hack Tied to China-Nexus APT
- GitHub — Notepad++ Supply Chain IOCs Repository
- ASEC AhnLab — February 2026 APT Group Trend Report
- MITRE ATT&CK — Lotus Blossom (G0030)
- Security Online — Supply Chain Poison: Lotus Blossom Hits Notepad++ to Deploy Chrysalis
Detection coverage for TL-2026-0214
As of 2026-03-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0214 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.