Skip to content

Notepad++ Attack Breakdown Reveals Sophisticated Malware and Actionable IoCs

Gbhackers •Divya • February 3, 2026

A complex espionage campaign attributed to Chinese APT group Lotus Blossom, active since 2009. The investigation uncovered a sophisticated compromise of Notepad++ distribution infrastructure that delivered Chrysalis, a previously undocumented custom backdoor with extensive remote access capabilities. The attack chain began at IP address 95.179.213.0, where execution of notepad++.exe and GUP.exe preceded download of a […]

Extracted Entities

APT Groups (1)

Attack Types (1)

IP Addresses (1)

Malware (1)