Lotus Blossom Hackers Compromise Notepad++ Hosting Infrastructure
Key Takeaways The state-sponsored threat group Lotus Blossom compromised the Notepad++ hosting infrastructure from June to December 2025. The attack targeted government, telecommunications, and...
Key Takeaways
- The state-sponsored threat group Lotus Blossom compromised the Notepad++ hosting infrastructure from June to December 2025.
- The attack targeted government, telecommunications, and critical infrastructure sectors globally, primarily in Southeast Asia.
- Attackers leveraged vulnerabilities in older WinGUp versions to distribute malicious installers, deploying Cobalt Strike or the Chrysalis backdoor.
- Notepad++ has released version 8.9.1 with significant security enhancements and moved to a new hosting provider.
A sophisticated campaign by the state-sponsored threat group Lotus Blossom successfully breached the official Notepad++ hosting environment between June and December 2025. This targeted operation specifically aimed at users within government agencies, telecommunications firms, and critical infrastructure entities.
Table Of Content
The attackers gained entry by compromising a shared hosting provider, enabling them to intercept and redirect traffic intended for the legitimate Notepad++ update server to their own malicious infrastructure. This infrastructure-level hijack allowed for precise targeting of victims, predominantly located in Southeast Asia, though the campaign also impacted organizations in South America, the United States, and Europe.
Notepad++ is a widely utilized open-source code editor, favored by system administrators, network engineers, and DevOps professionals in enterprise settings. These users frequently rely on the tool for tasks such as modifying server configurations, parsing system logs, and auditing code on secure systems where larger applications are impractical.
Analysts at Palo Alto Networks identified that compromising this specific tool provided attackers with a means to circumvent perimeter defenses and effectively gain administrative access to core network infrastructure by piggybacking on privileged user sessions.
Infection Mechanism and Technical Details
The attack vector exploited insufficient verification controls present in older iterations of WinGUp, the Notepad++ update component. When targeted users attempted to update their software, they unknowingly downloaded a malicious NSIS installer, named update.exe, which initiated a multi-stage infection process.
Unit 42 researchers uncovered two distinct attack sequences. One variant involved a Lua script injection that delivered the Cobalt Strike beacon malware, while the other utilized DLL sideloading techniques to deploy the custom Chrysalis backdoor. The malicious installer leveraged a legitimate Bitdefender component, BluetoothService.exe, to load a malicious library, log.dll, which subsequently decrypted and executed the backdoor.
Further activity observed between August and November 2025 indicated communication with command-and-control servers at IP addresses 45.76.155[.]202 and 45.77.31[.]210. Attackers frequently shifted between these servers to maintain persistent access to compromised systems.
The Chrysalis backdoor incorporated advanced evasion tactics to elude detection by security tools. Attackers employed the Microsoft Warbird code protection framework and custom API hashing methods to reduce antivirus detection while establishing persistent remote control. In the Lua script injection variant, malicious scripts were deployed using the EnumWindowStationsW API to inject shellcode and deliver the Cobalt Strike beacon.
The campaign targeted a broad array of sectors, including cloud hosting, energy, financial services, government, manufacturing, and software development across multiple continents. Successful beacons to malicious servers often occurred within seconds of payload download, with communications persisting for extended periods.
In response to these findings, Notepad++ has released version 8.9.1, which includes enhanced security measures such as certificate and signature verification for downloaded installers and XML signing of update server responses. The developers have also migrated to a new hosting provider with stronger security protocols and plan to enforce even stricter verification mechanisms starting with version 8.9.2.
What You Should Do
- Immediately update Notepad++ to version 8.9.1 or later to benefit from enhanced security features.
- Ensure all software, especially critical development and system administration tools, is updated regularly and verified from official, trusted sources.
- Implement robust endpoint detection and response (EDR) solutions to detect sophisticated malware and backdoor activity.
- Regularly audit network traffic for suspicious connections to known malicious IP addresses or unexpected command-and-control server communications.
- Educate users, particularly those with administrative privileges, about supply chain risks and the importance of verifying software integrity.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.