Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group

202/update/update.exe,” which was then launched by the legitimate Notepad++ updater process WinGUp.

  • Chain #2 featured a more sophisticated approach, including collecting system information and delivering different sets of payloads.
  • Chain #3 altered the distribution URL to “45.32.144255/update/update.exe” and initiated the same sequence described by Rapid7 above.
  • The variety in infection chains highlights the attackers’ creativity and their skillful avoidance of detection, making this a significant threat to the software ecosystem.