# Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556)

> Chinese state-sponsored group Lotus Blossom (Spring Dragon) compromised Notepad++ update infrastructure from June to December 2025 to deliver the previously undocumented Chrysalis backdoor and Cobalt Strike Beacon via trojanized NSIS installers. The campaign targeted government, telecommunications, aviation, energy, and software development organizations across Southeast Asia, South America, the United States, and Europe for espionage and persistent network access.

- **Published:** 2026-03-12T12:00:00Z
- **Last reviewed:** 2026-03-12T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0214
- **ID:** TL-2026-0214
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** PATCHED
- **Actor:** Lotus Blossom (China)
- **Detections:** 9 · **IOCs:** 38 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-15556

## Description

Between June and December 2025, the Chinese state-sponsored advanced persistent threat group Lotus Blossom (also tracked as Spring Dragon, Billbug, Thrip, Lotus Panda, and Raspberry Typhoon) conducted a sophisticated supply chain attack by compromising the hosting infrastructure used to distribute updates for Notepad++, one of the most widely used open-source text editors globally.

The attackers gained access to the hosting provider's server managing Notepad++ updates and selectively redirected update traffic for targeted users to attacker-controlled servers. Rather than conducting a mass compromise, the group employed surgical targeting — intercepting update requests from specific IP ranges or organizational networks and serving trojanized NSIS installers (update.exe) while allowing other users to receive legitimate updates unmodified.

Three distinct infection chains were identified:

Chain 1 (Cobalt Strike via Lua Injection): The malicious NSIS installer executes a compiled Lua script (alien.ini) that injects shellcode via the EnumWindowStationsW API, ultimately deploying a Cobalt Strike HTTPS Beacon for command-and-control operations. Artifacts are staged in %appdata%\Adobe\Scripts\.

Chain 2 (ProShow DLL Sideloading): A legitimate but vulnerable ProShow executable is dropped and used to sideload a malicious DLL, establishing persistence and delivering secondary payloads. Artifacts are staged in %appdata%\ProShow\.

Chain 3 (Chrysalis Backdoor via Bluetooth DLL Sideloading): The NSIS installer drops BluetoothService.exe (a renamed legitimate Bitdefender Submission Wizard binary) alongside a malicious log.dll. When BluetoothService.exe calls the exported functions LogInit and LogWrite, log.dll loads an encrypted shellcode blob, decrypts it using the XOR key 'CRAZY', and executes the Chrysalis backdoor. The backdoor creates a hidden directory at %appdata%\Bluetooth\ and establishes persistence via Windows services (T1543.003) and registry run keys (T1547.001).

The Chrysalis backdoor represents a significant evolution in Lotus Blossom's capabilities. It features custom API hashing using FNV-1a constants (base 0x811C9DC5, prime 0x1000193), RC4 encryption for configuration data (key: qwhvb^435h&*7) and C2 response decryption (key: vAuig34%^325hGV), and integration with Microsoft Warbird — an undocumented code protection framework — to cloak malicious shellcode via NtQuerySystemInformation with the SystemCodeFlowTransition operation (WbHeapExecuteCall). The backdoor supports a comprehensive command set including interactive shell access, file operations, process creation, drive enumeration, and data exfiltration over encrypted HTTPS channels.

C2 infrastructure was rotated throughout the campaign across multiple servers: 59.110.7.32:8880, 124.222.137.114:9999, api.skycloudcenter.com, and api.wiresguard.com. Additional infrastructure included domains cdncheck.it.com, safe-dns.it.com, and self-dns.it.com for payload staging and DNS-based communication. Data exfiltration was observed via temp.sh file upload service.

The vulnerability was assigned CVE-2025-15556 (CWE-494: Download of Code Without Integrity Check) reflecting the absence of cryptographic signature validation in the WinGUp update mechanism. Notepad++ released version 8.9.1 with XML signature validation (XMLDSig) and plans for enhanced signing enforcement in version 8.9.2.

Attribution to Lotus Blossom is assessed with high confidence based on infrastructure overlap with previously documented campaigns, the group's established use of DLL sideloading techniques, targeting patterns consistent with Chinese state espionage interests in Southeast Asian government and telecommunications sectors, and code-level similarities between the Chrysalis backdoor and the group's previously documented Sagerunex implant family.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1547 Boot or Logon Autostart Execution
- T1543 Create or Modify System Process
- T1574 Hijack Execution Flow
- T1134 Access Token Manipulation
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1480 Execution Guardrails
- T1070 Indicator Removal
- T1055 Process Injection
- T1620 Reflective Code Loading
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1005 Data from Local System
- T1074 Data Staged
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service

## Sources

- [Rapid7 — The Chrysalis Backdoor: A Deep Dive into Lotus Blossom's Toolkit](https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/)
- [Palo Alto Unit 42 — Nation-State Actors Exploit Notepad++ Supply Chain](https://unit42.paloaltonetworks.com/notepad-infrastructure-compromise/)
- [The Hacker News — Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom](https://thehackernews.com/2026/02/notepad-hosting-breach-attributed-to.html)
- [Tenable — FAQ: Notepad++ Supply Chain Compromise](https://www.tenable.com/blog/frequently-asked-questions-about-notepad-supply-chain-compromise)
- [Help Net Security — Notepad++ Supply Chain Attack: IOCs and Targets](https://www.helpnetsecurity.com/2026/02/03/notepad-supply-chain-attack-iocs-targets/)
- [The Register — Notepad++ Hijacking Linked to Chinese Lotus Blossom Crew](https://www.theregister.com/2026/02/02/notepad_hijacking_lotus_blossom/)
- [SOCRadar — Notepad++ Infrastructure Hijacked in State-Linked Supply Chain Attack](https://socradar.io/blog/notepad-infrastructure-hijacked/)
- [Security Affairs — Notepad++ Infrastructure Hack Tied to China-Nexus APT](https://securityaffairs.com/187570/apt/notepad-infrastructure-hack-likely-tied-to-china-nexus-apt-lotus-blossom.html)
- [GitHub — Notepad++ Supply Chain IOCs Repository](https://github.com/renat0z3r0/notepadpp-supply-chain-iocs)
- [ASEC AhnLab — February 2026 APT Group Trend Report](https://asec.ahnlab.com/ko/92884/)
- [MITRE ATT&CK — Lotus Blossom (G0030)](https://attack.mitre.org/groups/G0030/)
- [Security Online — Supply Chain Poison: Lotus Blossom Hits Notepad++ to Deploy Chrysalis](https://securityonline.info/supply-chain-poison-lotus-blossom-hits-notepad-to-deploy-chrysalis/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0214
