Billbug — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
February 2, 2026
Last Seen
February 9, 2026

Related Threat Clusters

  • State-Sponsored Hackers Compromise Notepad++ Update Mechanism

    Notepad++ has been hijacked by state-sponsored hackers, specifically a likely Chinese threat actor. The attackers compromised the software's update mechanism between June and December 2025, allowing them to redirect…

    100 articles · Updated February 2, 2026

Recent Intelligence Reports

  • Rapid7 links Lotus Blossom APT to Notepad++ compromise, delivering Chrysalis — Industrialcyber.Co · February 9, 2026
  • Notepad++ supply chain attack: Researchers reveal details, IoCs, targets — Feeds2.Feedburner · February 3, 2026
  • Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used — Cybersecuritynews · February 3, 2026
  • Notepad++ hijacking linked to Chinese Lotus Blossom crew — Theregister · February 2, 2026
  • Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor — Theregister · February 2, 2026
  • China-based espionage group compromised Notepad++ for six months — Cyberscoop · February 2, 2026

CVSS v3.1 Breakdown