Nation-State Actors Exploit Notepad++ Supply Chain

A state-sponsored threat group known as Lotus Blossom compromised the official hosting infrastructure for Notepad++ between June and December 2025. The attackers hijacked traffic to the update server, allowing them to selectively target specific users, primarily in Southeast Asia across government, telecommunications and critical infrastructure sectors. Two infection chains were identified - one using Lua script injection to deliver Cobalt Strike and another using DLL side-loading to deploy a Chrysalis backdoor. The campaign affected additional sectors in South America, US, Europe and Southeast Asia including cloud hosting, energy, financial, government, manufacturing and software development. The sophisticated supply chain attack leveraged insufficient verification controls in older versions of the Notepad++ updater.

Pulse ID: 699329ab4cfd86feb5b85024
Pulse Link: https://otx.alienvault.com/pulse/699329ab4cfd86feb5b85024
Pulse Author: AlienVault
Created: 2026-02-16 14:28:59

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Asia #BackDoor #Cloud #CobaltStrike #CyberSecurity #Europe #Government #InfoSec #LUA #Manufacturing #Notepad #OTX #OpenThreatExchange #SouthAmerica #SupplyChain #Telecom #Telecommunication #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
New beacon found at 172.104.48.174 on port 8443.
Please check it at https://www.beaconbeagle.com/beacons/172.104.48.174/x64 .
#ThreatIntel #CobaltStrike #Beacon
Beacon 172.104.48.174 x64

New beacon found at 172.104.48.174 on port 8443.
Please check it at https://www.beaconbeagle.com/beacons/172.104.48.174/x86 .
#ThreatIntel #CobaltStrike #Beacon
Beacon 172.104.48.174 x86

New beacon found at 47.109.45.70 on port 12345.
Please check it at https://www.beaconbeagle.com/beacons/47.109.45.70/x64 .
#ThreatIntel #CobaltStrike #Beacon
Beacon 47.109.45.70 x64

New beacon found at 47.109.45.70 on port 12345.
Please check it at https://www.beaconbeagle.com/beacons/47.109.45.70/x86 .
#ThreatIntel #CobaltStrike #Beacon
Beacon 47.109.45.70 x86

New beacon found at 118.89.73.78 on port 8088.
Please check it at https://www.beaconbeagle.com/beacons/118.89.73.78/x64 .
#ThreatIntel #CobaltStrike #Beacon
Beacon 118.89.73.78 x64

New beacon found at 118.89.73.78 on port 8088.
Please check it at https://www.beaconbeagle.com/beacons/118.89.73.78/x86 .
#ThreatIntel #CobaltStrike #Beacon
Beacon 118.89.73.78 x86

New beacon found at 47.236.130.154 on port 34567.
Please check it at https://www.beaconbeagle.com/beacons/47.236.130.154/x64 .
#ThreatIntel #CobaltStrike #Beacon
Beacon 47.236.130.154 x64

New beacon found at 47.236.130.154 on port 34567.
Please check it at https://www.beaconbeagle.com/beacons/47.236.130.154/x86 .
#ThreatIntel #CobaltStrike #Beacon
Beacon 47.236.130.154 x86

New beacon found at 119.91.54.176 on port 50001.
Please check it at https://www.beaconbeagle.com/beacons/119.91.54.176/x64 .
#ThreatIntel #CobaltStrike #Beacon
Beacon 119.91.54.176 x64