Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Notepad++ update chain hijacked by Chinese Lotus Blossom group

The cyberattack signals that Lotus Blossom operatives exploited a shared hosting server to redirect targeted users to malicious domains.

byEmre Çıtak
February 3, 2026
in Cybersecurity, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

Notepad++ developer Don Ho confirmed that Chinese government-affiliated hackers hijacked the open-source text editor’s update mechanism from June to December 2025, exploiting a shared server bug to deliver malicious updates to select users worldwide.

Don Ho detailed the incident in a blog post published on Monday. He attributed the cyberattack to hackers linked to the Chinese government, based on analyses of malware payloads and attack patterns conducted by multiple security experts. Ho stated that this affiliation “would explain the highly selective targeting” observed in the campaign. The attack involved redirecting certain users requesting software updates to a malicious server controlled by the hackers.

Rapid7, which investigated the breach, identified the perpetrators as the Lotus Blossom espionage group. This group operates on behalf of China and focuses on sectors including government, telecommunications, aviation, critical infrastructure, and media organizations. Lotus Blossom maintains a long track record of such operations, aligning with the patterns seen in the Notepad++ compromise.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Notepad++ qualifies as one of the longest-running open-source projects, with a history exceeding two decades. The software has accumulated at least tens of millions of downloads globally, reaching employees at various organizations across multiple countries. Its widespread adoption made it a viable vector for targeted intrusions.

Security researcher Kevin Beaumont first uncovered the cyberattack and documented his findings in December 2025. He reported that the hackers compromised a small number of organizations maintaining interests in East Asia. These compromises occurred after individuals within those organizations installed a tainted version of Notepad++. Beaumont noted that the attackers achieved “hands-on” access to the victims’ computers running the hijacked software versions.

Ho described the technical execution in his blog post. Notepad++’s website operated on a shared hosting server. The attackers specifically targeted the Notepad++ web domain, exploiting a software bug within it. This vulnerability enabled redirection of specific users to the hackers’ malicious server, which then served harmful updates. The malicious deliveries persisted until Ho patched the bug in November 2025, at which point the hackers’ access ended in early December 2025.

Ho referenced server logs showing the attackers’ subsequent efforts. The logs recorded attempts by the bad actor to re-exploit one of the fixed vulnerabilities, but these efforts failed following implementation of the patch. In an email to TechCrunch, Ho added that his hosting provider verified the compromise of the shared server without revealing the method of the initial breach.

Ho issued an apology for the incident in his communications. He recommended that all users download the most recent version of Notepad++, which incorporates the fix for the exploited bug. This update addresses the vulnerability that facilitated the redirection mechanism.

The Notepad++ incident parallels the 2019-2020 SolarWinds cyberattack. In that case, Russian government spies infiltrated SolarWinds servers. SolarWinds produces IT and network management tools used by large Fortune 500 organizations, including U.S. government departments. The spies inserted a backdoor into the company’s software updates. Once customers deployed these updates, the backdoor granted the spies access to data on the affected networks. The SolarWinds breach impacted agencies such as Homeland Security and the Departments of Commerce, Energy, Justice, and State.

Ho’s blog post and subsequent updates incorporated responses from him along with further details supplied by Rapid7.


Featured image credit

Tags: notepad++

Related Posts

Apple scraps Siri AI launch in the EU over intense regulatory clashes

Apple scraps Siri AI launch in the EU over intense regulatory clashes

June 9, 2026
Which devices will support macOS Golden Gate

Which devices will support macOS Golden Gate

June 9, 2026
Everything announced at WWDC26

Everything announced at WWDC26

June 9, 2026
Advanced SEO services for high impact digital strategies

Advanced SEO services for high impact digital strategies

June 8, 2026
The 8 best website builders for small businesses on any budget

The 8 best website builders for small businesses on any budget

June 8, 2026
Why European workloads are leaving US cloud in 2026

Why European workloads are leaving US cloud in 2026

June 8, 2026

LATEST NEWS

Apple scraps Siri AI launch in the EU over intense regulatory clashes

Which devices will support macOS Golden Gate

Everything announced at WWDC26

Advanced SEO services for high impact digital strategies

The 8 best website builders for small businesses on any budget

Why European workloads are leaving US cloud in 2026

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Roboto AI

Pickaxe

Pfpmaker

MindPal

Syllaby

ScreenApp

FinanceBrain

GitHub Spark

Hints

VisionStory AI

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.