Lotus Blossom is a cyber-espionage threat actor also tracked as Spring Dragon, Billbug, Thrip, and KTA529. The group is associated with supply-chain-style intrusion activity and malware delivery through trusted software distribution channels. In 2025, it was reported to have compromised Notepad++ hosting infrastructure over an extended period, intercepting software update traffic to deliver a previously undocumented backdoor known as CHRYSALIS. This activity demonstrates the actor’s ability to obtain initial access through upstream compromise, conduct post-exploitation malware deployment, and evade trust-based defenses by abusing legitimate update mechanisms. Based on the available facts, the group is linked to backdoor operations and software supply chain compromise, but the supplied information does not directly establish specific victim geographies, industry targeting, or a confirmed country of origin for this cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised the Notepad++ hosting/update infrastructure (June–Dec 2025) to hijack update traffic and deliver a previously undocumented backdoor (CHRYSALIS), consistent with a supply-chain/update-channel compromise.
Compromised Notepad++ hosting/update infrastructure to perform a supply-chain style attack, intercepting update traffic to deliver the CHRYSALIS backdoor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.