Notepad++ Update Infrastructure Hacked by Chinese APT Group Lotus Blossom

Mental Outlaw

Summary:

Notepad++, a popular free and open-source source code editor, was targeted in a sophisticated supply chain attack by a Chinese Advanced Persistent Threat (APT) group named Lotus Blossom. The hackers exploited the software's update infrastructure, not its source code, to deploy malware.

Key points:

  • Notepad++ is widely used by developers and system administrators due to its features and efficiency compared to default Notepad, bloated editors like VS Code, and complex ones like Vim.
  • The attack leveraged the "auto-update" feature, redirecting targeted users' update requests to a hacker-controlled server.
  • The malicious update.exe installer dropped a harmful DLL (log.dll) and an encrypted shellcode (BluetoothService).
  • log.dll performed DLL sideloading, decrypting and executing the shellcode to establish a persistent backdoor on the victim's machine.
  • Targeted organizations were primarily in East Asia, suggesting state-sponsored espionage by the Chinese government, potentially due to Notepad++'s history of expressing support for Taiwan, Hong Kong, Uyghurs, and Ukraine, and referencing the Tiananmen Square massacre.
  • Users are advised to update to the latest patched version and scan systems for Indicators of Compromise (IoCs).
  • Caution is recommended regarding automatic updates; verify the trustworthiness of the distribution mechanism.

Notepad++ Targeted by Chinese APT Group Lotus Blossom [0:00]

Why Notepad++ is a Popular Text Editor [0:34]

The Appeal of Notepad++ for Attackers [2:05]

The Supply Chain Attack Mechanism [2:20]

Chrysalis Backdoor Deployment [3:45]

Targets and Potential Motivations [5:30]

Recommendations for Users [7:25]