Chinese Lotus Blossom APT linked to Notepad++ supply-chain attack
The threat actor compromised of infrastructure associated with Notepad++ to deliver a previously undocumented backdoor, dubbed Chrysalis.
3 min read
Cybersecurity Help is a global vulnerability intelligence provider. We monitor vulnerabilities in software from 60,000+ vendors and help customers prevent potential data breaches by addressing them proactively.
Request DemoThe threat actor compromised of infrastructure associated with Notepad++ to deliver a previously undocumented backdoor, dubbed Chrysalis.
3 min readThe campaign, dubbed Operation Neusploit, was observed just three days after Microsoft revealed the flaw.
3 min readMasquerading as legitimate cryptocurrency trading automation tools, the packages, known as “skills,” deliver data-stealing malware.
3 min readAccording to CERT-UA, the flaw was weaponized within a day of Microsoft’s disclosure.
2 min readThe malicious updates embedded the GlassWorm malware loader and were pushed to users through normal update mechanisms.
2 min read