Chinese Lotus Blossom APT linked to Notepad++ supply-chain attack
The threat actor compromised of infrastructure associated with Notepad++ to deliver a previously undocumented backdoor, dubbed Chrysalis.
The threat actor compromised of infrastructure associated with Notepad++ to deliver a previously undocumented backdoor, dubbed Chrysalis.
The campaign, dubbed Operation Neusploit, was observed just three days after Microsoft revealed the flaw.
Masquerading as legitimate cryptocurrency trading automation tools, the packages, known as “skills,” deliver data-stealing malware.
According to CERT-UA, the flaw was weaponized within a day of Microsoft’s disclosure.
The malicious updates embedded the GlassWorm malware loader and were pushed to users through normal update mechanisms.
The attack involved an infrastructure-level breach at Notepad++’s hosting provider, not vulnerabilities in the application’s source code.
Mandiant is tracking the activity across multiple threat clusters, including UNC6661, UNC6671, and UNC6240.
Flare says it found more than 208,500 publicly exposed MongoDB servers, including 3,100 that required no authentication.
In brief: Ivanti, Microsoft and Fortinet fix zero-days, eScan hit with a supply chain attack, and more.
In a separate development, US authorities have seized the dark web and clearnet domains of the RAMP cybercrime forum.
Showing elements 351 - 360