#PlushDaemon
#ESETresearch discovered and analyzed a previously undocumented malicious tool for network devices that we have named #EdgeStepper, enabling China-aligned #PlushDaemon APT to perform adversary-in-the-middle to hijack updates to deliver malware. www.welivesecurity.com/en/eset-rese... 1/5
PlushDaemon compromises network devices for adversary-in-the-middle attacks
ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks.
www.welivesecurity.com
November 19, 2025 at 10:12 AM
#ESETresearch discovered + named 🇨🇳 China-aligned #APT group #PlushDaemon who did a supply-chain compromise of a 🇰🇷 South Korean #VPN provider, trojanizing its legitimate software installer with a Windows backdoor we named #SlowStepper www.welivesecurity.com/en/eset-rese...
🧵1/6
January 22, 2025 at 8:50 AM
🚨 PlushDaemon, a China-linked APT targeting S. Korea with a SlowStepper backdoor, SlowStepper. Using a supply chain attack, it infiltrates #VPN software to steal sensitive data.

Read: hackread.com/chinese-plus...

#CyberSecurity #PlushDaemon #APT #SlowStepper
Chinese PlushDaemon APT Targets S. Korean IPany VPN with Backdoor
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
January 23, 2025 at 8:45 PM
#SlowStepper is a feature-rich backdoor with a toolkit of more than 30 components. We analyzed and documented it in a previous blogpost about the compromise of a South Korean VPN service provider. www.welivesecurity.com/en/eset-rese... 4/5
PlushDaemon compromises supply chain of Korean VPN service
ESET researchers uncover a supply-chain attack against a VPN provider in South Korea by a new China-aligned APT group we have named PlushDaemon.
www.welivesecurity.com
November 19, 2025 at 10:12 AM
Join #ESETresearch at #JSAC2025!
Facundo Munoz will talk about China-aligned PlushDaemon APT compromising the supply chain of a 🇰🇷 South Korean VPN. In 2024, several users downloaded a trojanized NSIS installer from the official website of a South Korean VPN company. 🧵 1/3
January 22, 2025 at 12:54 AM
Great research here! "PlushDaemon" 👀
#ESETresearch discovered + named 🇨🇳 China-aligned #APT group #PlushDaemon who did a supply-chain compromise of a 🇰🇷 South Korean #VPN provider, trojanizing its legitimate software installer with a Windows backdoor we named #SlowStepper www.welivesecurity.com/en/eset-rese...
🧵1/6
January 22, 2025 at 5:14 PM
China's PlushDaemon Exploits DNS to Manipulate Software Updates

A sophisticated cyber threat linked to China is utilizing EdgeStepper to compromise DNS and hijack software updates.

substack.com/@pwnhackerne...

#Hacking #Cybercrime #Cybersecurity
November 20, 2025 at 4:13 PM
Chinese APT Infects Routers to Hijack Software Updates
Chinese APT Infects Routers to Hijack Software Updates
A unique take on the software update gambit has allowed "PlushDaemon" to evade attention as it mostly targets Chinese organizations.
www.darkreading.com
November 20, 2025 at 10:08 PM
TechNews ESET scopre il gruppo APT allineato alla Cina PlushDaemon
ESET scopre il gruppo APT allineato alla Cina PlushDaemon
l gruppo, impegnato in operazioni di cyberspionaggio, ha condotto un attacco alla supply chain di uno sviluppatore di VPN sudcoreano, sostituendo l'installer legittimo con uno contenente la backdoor SlowStepper, utilizzata esclusivamente da PlushDaemon
dlvr.it
January 28, 2025 at 6:07 PM
China-linked PlushDaemon used a compromised South Korean VPN installer (IPany) to spread malware since 2019. This malware stole data, including audio/video, from victims in South Korea, Japan, and China. ESET removed the malicious installer.#PlushDaemonMalware
January 23, 2025 at 3:11 AM
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates thehackernews.com/2025/11/edge...
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates
PlushDaemon hijacks software updates using EdgeStepper to redirect DNS traffic and deploy SlowStepper malware.
thehackernews.com
November 24, 2025 at 1:12 PM
O departamento de investigação da ESET descobriu um grupo de Ameaça Persistente Avançada ligado à China, até agora desconhecido, chamado PlushDaemon e envolvido em operações de ciberespionagem.
PlushDaemon: ESET revela ciberespionagem de grupo criminoso ligado à china
A ESET também identificou um ataque contra um popular serviço de VPN da Coreia do Sul. Saiba tudo sobre este caso.
pplware.sapo.pt
February 4, 2025 at 3:32 PM
📌 Chinese Cyberespionage Group PlushDaemon Exploits Software Updates with EdgeStepper Malware https://www.cyberhub.blog/article/16010-chinese-cyberespionage-group-plushdaemon-exploits-software-updates-with-edgestepper-malware
Chinese Cyberespionage Group PlushDaemon Exploits Software Updates with EdgeStepper Malware
The Chinese cyberespionage group PlushDaemon has been identified by ESET researchers as utilizing a malware strain named EdgeStepper to intercept software update traffic. This operation aims to compromise supply chains by exploiting the software update processes of targeted organizations. While specific technical details and the full extent of the impact remain undisclosed, the nature of the attack underscores significant risks to supply chain integrity. Supply chain attacks are particularly insidious due to their potential to affect a broad user base through a single compromised source. By intercepting and potentially altering software updates, attackers can distribute malware to all users who install the compromised updates. This method leverages the inherent trust users place in software vendors, making it an effective vector for large-scale infections. The technical implications of this attack are profound. Organizations must ensure the integrity of their software update mechanisms. This includes verifying digital signatures, monitoring network traffic for unusual patterns, and employing endpoint detection and response (EDR) solutions to detect and mitigate such threats. The involvement of a state-sponsored group like PlushDaemon suggests a high level of sophistication and targeting, necessitating advanced defensive measures. From a broader cybersecurity perspective, this incident highlights the critical need for robust supply chain security. Vendors must implement stringent security measures to protect their update mechanisms from compromise. Organizations should also enhance their threat intelligence capabilities to stay abreast of emerging threats and respond effectively. In conclusion, the PlushDaemon group's use of EdgeStepper malware to intercept software updates represents a significant threat to supply chain security. Organizations must adopt a multi-layered defense strategy to detect, prevent, and respond to such sophisticated attacks.
www.cyberhub.blog
November 26, 2025 at 10:40 AM
A previously undocumented China-aligned advanced persistent threat (APT) group named PlushDaemon has been linked to a supply chain attack targeting a South Korean virtual private network (VPN) provider in 2023, according to new findings from ESET.
thehackernews.com/2025/01/plus...
PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack
PlushDaemon APT targets South Korean VPN with SlowStepper backdoor. Multistage DNS C&C protocol aids espionage.
thehackernews.com
January 22, 2025 at 11:33 AM
Absolutely excellent threat intelligence here from @esetresearch.bsky.social on supply chain threat activity conducted by the newly identified PlushDaemon APT, a China-aligned group
#ESETresearch discovered + named 🇨🇳 China-aligned #APT group #PlushDaemon who did a supply-chain compromise of a 🇰🇷 South Korean #VPN provider, trojanizing its legitimate software installer with a Windows backdoor we named #SlowStepper www.welivesecurity.com/en/eset-rese...
🧵1/6
January 22, 2025 at 2:32 PM
ESET's Facundo Muñoz & Dávid Gábriš provide insights into how PlushDaemon performs adversary-in-the-middle attacks using a previously undocumented network implant that the researchers have named EdgeStepper. www.welivesecurity.com/en/eset-rese...
November 20, 2025 at 10:42 AM
韓國VPN業者IPany遭駭,攻擊者在原廠提供安裝檔上加料以散布惡意程式SlowStepper www.ithome.com.tw/news/167133
韓國VPN業者IPany遭駭,攻擊者在原廠提供安裝檔上加料以散布惡意程式SlowStepper
資安業者ESET揭露韓國VPN服務業者IPany遭遇供應鏈攻擊的事故,中國駭客組織PlushDaemon於安裝程式加入惡意程式碼,導致部分使用者下載後電腦被植入名為SlowStepper的後門程式
www.ithome.com.tw
January 24, 2025 at 8:50 AM
IPany, a South Korean VPN provider, suffered a supply chain attack by the PlushDaemon hacking group. The attackers compromised the VPN installer, deploying harmful malware that impacts customer systems. Stay informed and protect your networks. #cybersecurity #threat #VPNsecurity
IPany VPN Experiences Supply Chain Attack, Malware Deployed
South Korean VPN provider IPany experienced a supply chain attack by the PlushDaemon hacking group, which compromised its VPN installer and deployed malware affecting customer systems.
decrypt.lol
January 24, 2025 at 9:02 PM
ESET's Facundo Muñoz provides details on a China-aligned APT group tracked as PlushDaemon and one of its espionage operations: the supply-chain compromise in 2023 of VPN software developed by a South Korean company. www.welivesecurity.com/en/eset-rese...
January 23, 2025 at 10:35 AM
The website had been compromised by PlushDaemon since at least November 2023, resulting in users from 🇰🇷 South Korea, 🇨🇳 China, and 🇯🇵 Japan downloading the trojanized installer, which deployed the legitimate software
and SlowStepper. 2/6
January 22, 2025 at 8:53 AM
Supply chain of the company had been compromised and attackers had replaced the original installer with a trojanized one. We named the threat actor behind it PlushDaemon. It is a 🇨🇳 China-aligned group conducting cyberespionage operations since at least 2019. 2/3
January 22, 2025 at 12:55 AM