Inside Chrysalis: The New Reality of Supply Chain Attacks

Webinar Cover

In this session, Rapid7 Senior Director of Threat Analytics Christiaan Beek and Steve Edwards, Director of Threat Intelligence & Detection Engineering (TIDE) will walk through how attackers associated with the Lotus Blossom APT exploited compromised update infrastructure to selectively deliver a custom backdoor through legitimate Notepad++ updates. By abusing the software distribution process, not a flaw in the code, the attackers established and maintained access for months while evading widespread detection.

Webinar Snapshot

You’ll learn how the exploitation unfolded, why this attack matters far beyond Notepad++, and how this same technique is being used to quietly compromise environments that rely on trusted software supply chains.

Attendees will walk away with:

  • A clear breakdown of how the update mechanism was exploited and why it bypassed traditional controls
  • Practical steps to assess exposure to similar supply chain exploitation in your environment
  • Detection and response guidance for identifying patient, highly selective supply chain threats