Inside Chrysalis Webinar

Webinar Cover

In this session, Rapid7 Senior Director of Threat Analytics Christiaan Beek and Steve Edwards, Director of Threat Intelligence & Detection Engineering (TIDE) will walk through how attackers associated with the Lotus Blossom APT exploited compromised update infrastructure to selectively deliver a custom backdoor through legitimate Notepad++ updates. By abusing the software distribution process, not a flaw in the code, the attackers established and maintained access for months while evading widespread detection.

Webinar Snapshot

You’ll learn how the exploitation unfolded, why this attack matters far beyond Notepad++, and how this same technique is being used to quietly compromise environments that rely on trusted software supply chains.

Attendees will walk away with:

  • A clear breakdown of how the update mechanism was exploited and why it bypassed traditional controls
  • Practical steps to assess exposure to similar supply chain exploitation in your environment
  • Detection and response guidance for identifying patient, highly selective supply chain threats

RECAPTCHA

By clicking below you agree to our privacy policy, confirm that you are over the age of 16, and that we and Rapid7 can contact you for marketing purposes via email, social, digital ads, post and telephone.