BLOG

How a "Trust-Centric" protection layer is reinventing Internet security? 

In 2025, the sophistication of a supply chain attack demonstrated a brutal reality: even the most ordinary trusted tool can become a perfect weapon for malicious actors.

Between June and December 2025, hackers carried out a highly sophisticated supply chain attack (editor's note: Chrysalis) targeting the update mechanism of Notepad++, a very popular text editor used and downloaded around 80,000 times a day. Rather than attacking the Notepad++ source code base, it was the shared hosting provider used to perform software updates that was compromised. This enabled them to intercept and manipulate the network traffic of many companies, silently distributing malicious installations, particularly to selected targets such as cybersecurity solutions. Many systems were hacked, leading to massive compromises of critical data.

How did the Chrysalis attack work?

The Notepad++ update program (WinGUp) requested an XML file containing the URL of the latest installer. Previous versions of WinGUp had no certificate validation or signature validation system, which meant thatthey blindly trusted any URL returned by the server. Attackers exploited this weakness by intercepting the XML response and replacing the legitimate Notepad++ update download link with a malicious link under their control.

As a result, Notepad++ users who clicked on "Check for Updates" downloaded and ran an installer riddled with spyware, thinking it was trustworthy. Since Notepad++ is widely used in many industries, the victims of this highly sophisticated attack included not only individuals but also corporate and government organizations. This is how a seemingly harmless software update program was hijacked over a six-month period.

Why have traditional threat-focused security systems failed?

Instead of attacking the software itself, the attackers compromised its hosting provider. This gave them terrifying power: the ability to silently replace legitimate update links with malicious installers, directly within a software update stream that was considered trustworthy.

No alarms. No red flags.

Just a seemingly normal update that delivered spyware to carefully selected victims. For six months, the operation remained invisible, spying on data traffic, stealing internal credentials, and leaving almost no legal digital trace.

Traditional threat-centric security solutions such as EDRs were unable to detect the Chrysalis attack because they are designed to look for suspicious behavior. In the context of this attack:

  • Chrysalis arrived via a reputable update channel without any suspicion about its origin. The malware did not enter machines as an unknown binary, but through a legitimate Notepad++ update stream, normally approved by security controls.
  • EDRs analyze indicators of compromise such as source reputation, process lineage, and expected behavior, while Chrysalis arrived via a signed, approved, and expected update process.
  • Chrysalis used side-loading of DLLs, exploiting the normal Windows search order that is not filtered by EDRs, by placing a malicious DLL next to a legitimate executable.
  • The backdoor was silent, low-noise, and geared toward espionage with objectives other than encryption or data destruction.
  • Finally, the Chrysalis malware operated "within the trusted zone," where security controls are more permissive.

Redefining the concept of trust in Internet security is no longer an option.

Chrysalis was not just another attack, but a warning demonstrating the power of a carefully crafted attack. It revealed the urgency of strengthening all existing protective shields with a proactive approach that complements reactive, threat-focused solutions.

Ekinops' Zero Trust Internet Access (ZTIA) technology only allows Internet access to verified and legitimate domains, eliminating the risks associated with unidentified content while protecting against web-based cyberattacks, including the most complex ones such as Chrysalis. Traditional "threat-centric" security models not only struggle to counter the ultra-sophistication of new attacks, but also struggle to counter the explosion of new malware that emerges every day from new malicious sites. Ekinops' Zero Trust Internet Access (ZTIA) provides information systems with a reliable, non-permissive security layer focused on trust: access to unknown and unverified URLs is simply blocked. Ekinops is a global provider of open, reliable, and innovative network connectivity solutions for telecommunications operators and enterprises worldwide. Ekinops is listed on Euronext Paris. In June 2025, Ekinops acquired Olfeo, a French cybersecurity company specializing in secure Internet access through its Security Service Edge (SSE) platform since 2003. This alliance has created a leading European SASE provider that unifies connectivity, network security, and access control.

At the heart of Olfeo by Ekinops solutions is the exclusive Zero Trust Internet Access technology, which protects information systems by only allowing legitimate and verified web content, covering more than 99% of web requests. Combined with Ekinops SD-WAN, it offers the first European solution that provides both optimized network performance and secure access to applications.

Available in SaaS or On-Premise models, Olfeo by Ekinops solutions are quick to deploy and include advanced cybersecurity features such as SWG, DNS, CASB, and DLP.

Trusted by more than 500 organizations—mid-size companies, large enterprises, ministries, hospitals, and local authorities—Olfeo by Ekinops is recognized for its technological excellence and proudly carries the “Used by the French Army” and “France Cybersecurity” labels, reflecting its quality and reliability.

For more information, contact us to request a demo.