Time to use something simpler!
Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs - update.exe downloaded ...
Turns out Windows is fast when you stop using the Start menu ...
Rapid7 links China-linked Lotus Blossom to a 2025 Notepad++ hosting breach that delivered the Chrysalis backdoor via hijacked updates, fixed in v8.8.9 ...
The hosting provider's compromise allowed attackers to deliver malware through tainted software updates for six months.
Notepad++ update servers were compromised for 6 months in 2025. Learn how the Chrysalis backdoor targeted users and why you must manually update to version 8.9.1 now.
一些您可能无法访问的结果已被隐去。
显示无法访问的结果