Chrysalis is a Windows backdoor associated with the China-linked espionage group Lotus Blossom, also tracked as Billbug, Spring Dragon, Thrip, Lotus Panda, Raspberry Typhoon, and related aliases. It emerged publicly in connection with the 2025 compromise of Notepad++ update infrastructure, where selectively targeted users received trojanized updates through a supply-chain intrusion affecting the updater trust chain rather than the editor’s source code.
In observed delivery chains, Chrysalis was deployed through DLL sideloading using a legitimate renamed executable that loaded a malicious DLL, which then decrypted and executed the backdoor payload from an encrypted component. Reporting also ties the broader campaign to trojanized NSIS installers, multi-stage loaders, and follow-on deployment alongside Cobalt Strike Beacon and Metasploit components. The malware and surrounding loader chain used defense-evasion measures including Microsoft Warbird obfuscation, encrypted payloads and configuration data, and custom API hashing to conceal Windows API usage.
Chrysalis is a full-featured remote access implant designed for persistent espionage access on Windows systems. Documented capabilities include establishing persistence through registry modifications or service installation, spawning an interactive reverse shell, executing remote processes, reading and writing files, uploading data, collecting host information, and removing itself through a self-destruct or self-uninstall routine. Campaign reporting also links the intrusion set to system information collection and file exfiltration. Command-and-control traffic was crafted to resemble legitimate API-style web traffic, supporting stealth during post-compromise operations.
The malware has been linked to highly selective targeting of government, telecommunications, financial, IT services, software development, aviation, and other strategic sectors across multiple regions. Its tradecraft and deployment patterns align with Lotus Blossom’s long-running intelligence-collection operations, particularly the group’s use of trusted software distribution channels, DLL sideloading, and custom backdoors for covert long-term access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Lotus Blossom exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor. | Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Rapid7 Labs attributed the Notepad++ supply chain compromise to the China-linked threat group Lotus Blossom ... Their report reveals that the attackers deployed a previously undocumented, sophisticated backdoor dubbed “Chrysalis,” which was delivered via a trojanized NSIS installer named update.exe after the Notepad++ users’ update traffic was selectively redirected.
Threat group KTA529 (also known as Lotus Blossom, Spring Dragon, Billbug and Thrip) compromised Notepad++ hosting infrastructure between June and December 2025, intercepting update traffic to deliver a previously undocumented backdoor named CHRYSALIS.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
the attack was not a vulnerability in the Notepad++ code itself, but a supply chain compromise of the project’s hosting infrastructure, which allowed attackers to selectively redirect update traffic to serve malicious files to specific targets.
Insikt Group created Sigma rules to detect update.exe's execution of reconnaissance commands (whoami, tasklist, systeminfo, and netstat -ano) and curl commands for system information exfiltration.
The primary payload is a previously undocumented, feature-rich backdoor dubbed “Chrysalis.” It supports 16 distinct commands, including interactive shell access
Description Lotus Blossom TinyCC shellcode execution simulation. Svchost.exe executed with TinyCC compiler flags (-nostdlib -run) to simulate Chrysalis backdoor's shellcode compilation technique.
Attackers used a sophisticated loader that leverages Microsoft Warbird, an undocumented internal Windows code-protection framework. This allowed them to execute malicious shellcode while masquerading as a legitimate, Microsoft-signed binary, effectively bypassing many security solutions.
This allowed them to execute malicious shellcode while masquerading as a legitimate, Microsoft-signed binary
It supports 16 distinct commands, including interactive shell access, file manipulation, and self-uninstallation to hide its tracks.
"...Bluetooth\\Bluetooth,Encrypted shellcode blob (no extension)"
"Detects payload bytes in first 0x490 bytes in clipc.dll Warbird technique... scope = 'Microsoft signed DLL - clipc.dll'"
C2 (Command and Control) traffic designed to mimic DeepSeek API endpoints to blend in with legitimate network traffic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor campaign used in the evaluation scenario, involving DLL side-loading on a Windows host where BluetoothService.exe loads a malicious log.dll.
A malicious backdoor delivered via a supply chain compromise of the official Notepad++ update infrastructure to targeted users.
A custom backdoor delivered through the compromised Notepad++ update mechanism during Lotus Blossom's campaign.
공급망 침해 과정에서 배포된 백도어로, 감염 후 시스템 정보 수집, 원격 명령 실행, 파일 유출을 가능하게 한다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.