Notepad++ Update mechanism compromised

Exact mechanism unknown, but this is wild: Notepad++ Hijacked by State-Sponsored Hackers | Notepad++

Impacted versions: 8.8.6 - 8.8.8 if I’m reading this right.

Beaumont had this a while ago, but the compromise was still ongoing, it seems.

https://doublepulsar.com/small-numbers-of-notepad-users-reporting-security-woes-371d7a3fd2d9

Beaumont is saying the update process may not have bumped version numbers, so basically all versions are suspect.

IOCs here: The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit

Incredibly rich set of IoCs here: https://securelist.com/notepad-supply-chain-attack/118708/

URLs used for malicious Notepad++ update deployments
hxxp[://]45[.]76[.]155[.]202/update/update[.]exe
hxxp[://]45[.]32[.]144[.]255/update/update[.]exe
hxxp[://]95[.]179[.]213[.]0/update/update[.]exe
hxxp[://]95[.]179[.]213[.]0/update/install[.]exe
hxxp[://]95[.]179[.]213[.]0/update/AutoUpdater[.]exe

System information upload URLs
hxxp[://]45[.]76[.]155[.]202/list
hxxps[://]self-dns[.]it[.]com/list

URLs used by Metasploit downloaders to deploy Cobalt Strike beacons
hxxps[://]45[.]77[.]31[.]210/users/admin
hxxps[://]cdncheck[.]it[.]com/users/admin
hxxps[://]safe-dns[.]it[.]com/help/Get-Start

URLs used by Cobalt Strike Beacons delivered by malicious Notepad++ updaters
hxxps[://]45[.]77[.]31[.]210/api/update/v1
hxxps[://]45[.]77[.]31[.]210/api/FileUpload/submit
hxxps[://]cdncheck[.]it[.]com/api/update/v1
hxxps[://]cdncheck[.]it[.]com/api/Metadata/submit
hxxps[://]cdncheck[.]it[.]com/api/getInfo/v1
hxxps[://]cdncheck[.]it[.]com/api/FileUpload/submit
hxxps[://]safe-dns[.]it[.]com/resolve
hxxps[://]safe-dns[.]it[.]com/dns-query

URLs used by the Chrysalis backdoor and the Cobalt Strike Beacon payloads associated with it, as previously identified by Rapid7
hxxps[://]api[.]skycloudcenter[.]com/a/chat/s/70521ddf-a2ef-4adf-9cf0-6d8e24aaa821
hxxps[://]api[.]wiresguard[.]com/update/v1
hxxps[://]api[.]wiresguard[.]com/api/FileUpload/submit

URLs related to Cobalt Strike Beacons uploaded to multiscanners, as previously identified by Rapid7
hxxp[://]59[.]110[.]7[.]32:8880/uffhxpSy
hxxp[://]59[.]110[.]7[.]32:8880/api/getBasicInfo/v1
hxxp[://]59[.]110[.]7[.]32:8880/api/Metadata/submit
hxxp[://]124[.]222[.]137[.]114:9999/3yZR31VK
hxxp[://]124[.]222[.]137[.]114:9999/api/updateStatus/v1
hxxp[://]124[.]222[.]137[.]114:9999/api/Info/submit
hxxps[://]api[.]wiresguard[.]com/users/system
hxxps[://]api[.]wiresguard[.]com/api/getInfo/v1

Malicious updater[.]exe hashes
8e6e505438c21f3d281e1cc257abdbf7223b7f5a
90e677d7ff5844407b9c073e3b7e896e078e11cd
573549869e84544e3ef253bdba79851dcde4963a
13179c8f19fbf3d8473c49983a199e6cb4f318f0
4c9aac447bf732acc97992290aa7a187b967ee2c
821c0cafb2aab0f063ef7e313f64313fc81d46cd

Hashes of malicious auxiliary files
06a6a5a39193075734a32e0235bde0e979c27228 — load
9c3ba38890ed984a25abb6a094b5dbf052f22fa7 — load
ca4b6fe0c69472cd3d63b212eb805b7f65710d33 — alien[.]ini
0d0f315fd8cf408a483f8e2dd1e69422629ed9fd — alien[.]ini
2a476cfb85fbf012fdbe63a37642c11afa5cf020 — alien[.]ini

Malicious file hashes, as previously identified by Rapid7
d7ffd7b588880cf61b603346a3557e7cce648c93
94dffa9de5b665dc51bc36e2693b8a3a0a4cc6b8
21a942273c14e4b9d3faa58e4de1fd4d5014a1ed
7e0790226ea461bcc9ecd4be3c315ace41e1c122
f7910d943a013eede24ac89d6388c1b98f8b3717
73d9d0139eaf89b7df34ceeb60e5f8c7cd2463bf
bd4915b3597942d88f319740a9b803cc51585c4a
c68d09dd50e357fd3de17a70b7724f8949441d77
813ace987a61af909c053607635489ee984534f4
9fbf2195dee991b1e5a727fd51391dcc2d7a4b16
07d2a01e1dc94d59d5ca3bdf0c7848553ae91a51
3090ecf034337857f786084fb14e63354e271c5d
d0662eadbe5ba92acbd3485d8187112543bcfbf5
9c0eff4deeb626730ad6a05c85eb138df48372ce

Malicious file paths
%appdata%\ProShow\load
%appdata%\Adobe\Scripts\alien[.]ini
%appdata%\Bluetooth\BluetoothService

2 Likes

Some more!

45.32.144[.]255 - possible malicious download IP, active 2025-09-28 through 2025-10-12
160.250.93[.]48 - IP used by C2 domains api.skycloudcenter[.]com and api.cloudtrafficservice[.]com starting 2025-12-04
cloudtrafficservice[.]com
api[.]cloudtrafficservice[.]com - C2 domain active since 2025-12-03
103.159.133[.]178 - possible origin IP for Cobalt Strike beacon domain wiresguard[.]com
2 Likes