Chrysalis is a Windows backdoor attributed with moderate confidence to the China-linked Lotus Blossom espionage group. It was deployed in a highly selective 2025 compromise of Notepad++ update infrastructure, in which targeted users received trojanized update installers. One observed execution chain used DLL side-loading: a renamed legitimate security-product executable loaded a malicious library that decrypted and executed the Chrysalis payload. Chrysalis uses obfuscation including Microsoft Warbird protection and custom API hashing to hinder analysis and detection. It communicates with command-and-control infrastructure over HTTPS using API-like request patterns, collects host information, and supports interactive shell access, process execution, file operations including upload, persistence, and self-uninstallation. The campaign targeted government, telecommunications, financial, IT services, and other strategically relevant organizations, with victims reported across Southeast Asia, Central America, Australia, the United States, and Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Lotus Blossom exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor. | Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Rapid7 Labs attributed the Notepad++ supply chain compromise to the China-linked threat group Lotus Blossom ... Their report reveals that the attackers deployed a previously undocumented, sophisticated backdoor dubbed “Chrysalis,” which was delivered via a trojanized NSIS installer named update.exe after the Notepad++ users’ update traffic was selectively redirected.
Threat group KTA529 (also known as Lotus Blossom, Spring Dragon, Billbug and Thrip) compromised Notepad++ hosting infrastructure between June and December 2025, intercepting update traffic to deliver a previously undocumented backdoor named CHRYSALIS.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
the attack was not a vulnerability in the Notepad++ code itself, but a supply chain compromise of the project’s hosting infrastructure, which allowed attackers to selectively redirect update traffic to serve malicious files to specific targets.
Insikt Group created Sigma rules to detect update.exe's execution of reconnaissance commands (whoami, tasklist, systeminfo, and netstat -ano) and curl commands for system information exfiltration.
The primary payload is a previously undocumented, feature-rich backdoor dubbed “Chrysalis.” It supports 16 distinct commands, including interactive shell access
Description Lotus Blossom TinyCC shellcode execution simulation. Svchost.exe executed with TinyCC compiler flags (-nostdlib -run) to simulate Chrysalis backdoor's shellcode compilation technique.
Attackers used a sophisticated loader that leverages Microsoft Warbird, an undocumented internal Windows code-protection framework. This allowed them to execute malicious shellcode while masquerading as a legitimate, Microsoft-signed binary, effectively bypassing many security solutions.
This allowed them to execute malicious shellcode while masquerading as a legitimate, Microsoft-signed binary
It supports 16 distinct commands, including interactive shell access, file manipulation, and self-uninstallation to hide its tracks.
"...Bluetooth\\Bluetooth,Encrypted shellcode blob (no extension)"
"Detects payload bytes in first 0x490 bytes in clipc.dll Warbird technique... scope = 'Microsoft signed DLL - clipc.dll'"
C2 (Command and Control) traffic designed to mimic DeepSeek API endpoints to blend in with legitimate network traffic.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A simulated backdoor campaign used in the evaluation framework. It involves DLL side-loading on a Windows host, in which BluetoothService.exe loads a malicious log.dll; the scenario includes investigation of associated execution, DLL-load, C2, and DNS activity.
A backdoor campaign used in the evaluation scenario, involving DLL side-loading on a Windows host where BluetoothService.exe loads a malicious log.dll.
A malicious backdoor delivered via a supply chain compromise of the official Notepad++ update infrastructure to targeted users.
A custom backdoor delivered through the compromised Notepad++ update mechanism during Lotus Blossom's campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.