Lotus Blossom
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Lotus Blossom, also tracked under the alias Billbug, is a threat actor publicly attributed to China and described as a Chinese state‑sponsored group. The actor’s known aliases appear in multiple public reports linking the group to espionage‑focused operations. Its geographic origin is consistently identified as China in the available open‑source assessments. No further details about its size, internal structure, or funding are disclosed in the referenced material.
In June 2025 the group carried out a supply‑chain compromise of the Notepad++ software update mechanism by seizing control of the project’s shared hosting provider. By redirecting legitimate update traffic to malicious servers, the attackers distributed a custom backdoor named Chrysalis alongside widely used post‑exploitation frameworks such as Cobalt Strike and Metasploit to a targeted subset of users. The intrusion persisted for several months despite the hosting provider’s scheduled maintenance because the threat actors retained stolen credentials that allowed continuous interception of update requests. Detection was hampered as the malicious updates blended with normal developer activity, evading many endpoint detection and response tools that rely on behavioral trust models. In response, the Notepad++ project migrated to a new hosting provider and strengthened its updater to enforce certificate and signature verification for all future releases.
The observed tactics, techniques, and procedures from this operation include gaining initial access through the compromise of a third‑party hosting service, leveraging stolen credentials to maintain persistent access, and employing a dual‑tool approach that combines a bespoke backdoor with established offensive frameworks. The use of a supply‑chain vector to deliver both a custom payload and legitimate‑looking security tools illustrates a focus on stealth and longevity in victim environments. These tactics reflect a pattern of exploiting trusted software distribution channels to achieve prolonged access without triggering conventional alerts. The incident underscores the importance of verifying update integrity and monitoring for anomalous credential use in supply‑chain defenses.
Incidents
Attributed incidents are available to members.
1 incident