Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Notepad++ Compromised by Chinese APT Group with Custom Malware

Notepad++ Compromised by Chinese APT Group with Custom Malware

Posted on February 3, 2026 By CWS

Key Points

  • Chinese APT group Lotus Blossom targeted Notepad++ users.
  • Custom malware ‘Chrysalis’ was used in the espionage campaign.
  • Targets included government and critical infrastructure sectors.

Espionage Campaign Overview

A recent sophisticated cyber espionage operation, linked to the Chinese Advanced Persistent Threat (APT) group known as Lotus Blossom, has compromised Notepad++ users. The campaign involves deploying a custom-designed backdoor, dubbed ‘Chrysalis’, through compromised infrastructure. This operation has primarily affected entities in sectors such as government, telecommunications, and aviation across Southeast Asia and Central America.

The breach was uncovered by Ivan Feigl, a researcher from Rapid7. The initial investigation was triggered by a security incident involving the execution of a malicious file named update[.]exe. This file was downloaded from a suspicious IP address, 95.179.213[.]0, after the legitimate Notepad++ and its updater were executed.

Technical Details of the Attack

The malicious update[.]exe file is an NSIS installer, a tool that Chinese APTs commonly exploit for delivering initial payloads. Upon execution, it creates a hidden directory in the %AppData% folder named ‘Bluetooth’, where several files, including BluetoothService.exe and log.dll, are dropped.

The BluetoothService.exe file is a legitimate Bitdefender Submission Wizard binary but is misused by the attackers for DLL sideloading. This technique forces the binary to load the malicious log.dll instead of the genuine library, which in turn decrypts and executes the Chrysalis backdoor.

Chrysalis Backdoor Capabilities

The Chrysalis backdoor is a sophisticated piece of malware designed for long-term infiltration. It employs several advanced techniques, such as custom encryption and API hashing, to evade detection. It communicates with its command and control server over HTTPS, mimicking legitimate network traffic to avoid raising suspicions.

  • Interactive Shell: Capable of spawning a reverse shell.
  • File Operations: Includes reading, writing, and deleting files.
  • Process Execution: Can launch remote processes.
  • Self-Removal: Includes a mode for removing itself from the system.

Advanced Techniques and Attribution

The attack chain also includes a loader variant that uses Microsoft Warbird, a complex code protection framework, to obscure its execution flow. By exploiting the NtQuerySystemInformation system call, the loader decrypts and runs shellcode in a manner that bypasses user-mode hooks and standard monitoring tools.

Attribution to Lotus Blossom is based on the use of specific techniques, such as Bitdefender sideloading, and shared cryptographic keys found in related malware.

Conclusion

This incident underscores the ongoing threat posed by advanced cyber actors targeting critical sectors. Organizations must remain vigilant and employ robust security measures to defend against such sophisticated attacks.

Frequently Asked Questions

Q: What is Chrysalis backdoor?
A: Chrysalis is a custom backdoor used by the APT group for long-term infiltration and data exfiltration.

Q: How does the attack affect Notepad++ users?
A: The attack compromises the infrastructure hosting Notepad++, potentially targeting users in specific sectors.

Q: What sectors are most at risk?
A: Government, telecommunications, and aviation sectors are primarily targeted.

Q: How can organizations protect themselves?
A: Implementing advanced security measures and monitoring unusual network activity can help mitigate such threats.

Q: Who is attributed to this attack?
A: The attack is attributed to the Chinese APT group Lotus Blossom with moderate confidence.

Cyber Security News Tags:Chinese APT, Chrysalis backdoor, cyber espionage, Cybersecurity, government sectors, Lotus Blossom, Malware, Notepad, Southeast Asia, Telecommunications

Post navigation

Previous Post: Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users
Next Post: Notepad++ Hosting Compromise Linked to Chinese Hackers

Related Posts

Microsoft Investigating Forms Service Issue Not Accessible for Users Microsoft Investigating Forms Service Issue Not Accessible for Users Cyber Security News
Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach Cyber Security News
Ransomware Tactics Evolve Beyond Vulnerable Drivers Ransomware Tactics Evolve Beyond Vulnerable Drivers Cyber Security News
Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors Cyber Security News
Janela RAT Malware Targets Latin American Financial Sector Janela RAT Malware Targets Latin American Financial Sector Cyber Security News
U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark