#PlushDaemon
🟢 PlushDaemon Group Exploits Software Updates for Supply Chain Attacks

🗨️ The China-linked PlushDaemon group is conducting cyber-espionage operations by intercepting software update traffic with…

#news
PlushDaemon Group Exploits Software Updates for Supply Chain Attacks
Read more
hackmag.com
March 27, 2026 at 5:40 PM
Notícia da BleepingComputer

"‘PlushDaemon’ hackers hijack software updates in supply-chain attacks" #bolhasec
‘PlushDaemon’ hackers hijack software updates in supply-chain attacks
The China-aligned advanced persistent threat (APT) tracked as 'PlushDaemon' is hijacking software update traffic to deliver malicious payloads to its targets.
www.bleepingcomputer.com
January 2, 2026 at 1:30 PM
‘PlushDaemon’ハッカーがサプライチェーン攻撃でソフトウェア更新を乗っ取り

‘PlushDaemon’として追跡されている中国関与の脅威アクターが、EdgeStepperと呼ばれる新たなインプラントを用いてソフトウェア更新トラフィックを乗っ取り、サイバースパイ活動を行っています。 2018年以降、PlushDaemonのハッカーは、SlowStepperバックドアなどのカスタムマルウェアを用いて、米国、中国、台湾、香港、韓国、ニュージーランドの個人および組織を標的にしてきました。…
‘PlushDaemon’ハッカーがサプライチェーン攻撃でソフトウェア更新を乗っ取り
‘PlushDaemon’として追跡されている中国関与の脅威アクターが、EdgeStepperと呼ばれる新たなインプラントを用いてソフトウェア更新トラフィックを乗っ取り、サイバースパイ活動を行っています。 2018年以降、PlushDaemonのハッカーは、SlowStepperバックドアなどのカスタムマルウェアを用いて、米国、中国、台湾、香港、韓国、ニュージーランドの個人および組織を標的にしてきました。 PlushDaemonは、電子機器メーカー、大学、そしてカンボジアにある日本の自動車製造工場を侵害しています。サイバーセキュリティ企業ESETのテレメトリーデータによると、2019年以降、この脅威アクターは標的ネットワークへの侵入に悪意あるアップデートを利用してきたことが示されています。 2023年以降のPlushDaemonの被害者出典: ESET 攻撃チェーン 攻撃者は既知の脆弱性や弱い管理者パスワードを悪用してルーターにアクセスし、EdgeStepperインプラントをインストールしたうえで、ソフトウェア更新トラフィックを自らのインフラへリダイレクトします。 EdgeStepperは、DNSクエリを傍受し、そのドメインがソフトウェア更新の配信に使われていることを確認した後に、それらを悪意あるDNSノードへリダイレクトすることで機能すると、ESETの研究者はBleepingComputerと共有したレポートの中で説明しています。 被害者がソフトウェアを更新しようとすると、Windows向けマルウェアダウンローダーであるLittleDaemonを、‘popup_4.2.0.2246.dll’という名前のDLLファイルに偽装した形で受け取ります。 攻撃の概要出典: ESET LittleDaemonは、DaemonicLogisticsという別のマルウェアドロッパーを取得し、メモリ上で復号・実行して、PlushDaemonの代表的なバックドアであるSlowStepperを取得します。 このバックドアは、韓国製VPN製品IPanyのユーザーに対する攻撃において以前に文書化されています。その攻撃では、ユーザーはベンダーの公式サイトからトロイの木馬化されたインストーラーをダウンロードしていました。 SlowStepperマルウェアにより、ハッカーは詳細なシステム情報の収集、広範なファイル操作の実行、コマンドの実行、そしてブラウザからのデータ窃取、キーストロークの傍受、認証情報の収集が可能な、さまざまなPythonベースのスパイウェアツールの実行が可能になります。 翻訳元:
blackhatnews.tokyo
December 5, 2025 at 2:14 AM
PlushDaemon Group Reroutes Software Updates to Deploy Espionage Tools #China #CyberAttacks #Cyberespionage
PlushDaemon Group Reroutes Software Updates to Deploy Espionage Tools
  A cyberespionage group known in security research circles as PlushDaemon has been carrying out a long-running operation in which they take advantage of software update systems to secretly install their own tools on targeted computers. According to new analysis by ESET, this group has been active for several years and has repeatedly improved its techniques. Their operations have reached both individuals and organizations across multiple regions, including areas in East Asia, the United States, and Oceania. Victims have included universities, companies that manufacture electronics, and even a major automotive facility located in Cambodia. ESET’s data suggests that this shift toward manipulating software updates has been a consistent part of PlushDaemon’s strategy since at least 2019, which indicates the group has found this method to be reliable and efficient. The attackers begin by attempting to take control of the network equipment that people rely on for internet connectivity, such as routers or similar devices. They usually exploit security weaknesses that are already publicly known or take advantage of administrators who have left weak passwords unchanged. Once the attackers get access to these devices, they install a custom-built implant researchers call EdgeStepper. This implant is written in the Go programming language and compiled in a format that works comfortably on Linux-based router systems. After deployment, EdgeStepper operates quietly in the background, monitoring how the device handles internet traffic. What makes this implant dangerous is its ability to interfere with DNS queries. DNS is the system that helps computers find the correct server whenever a user tries to reach a domain name. EdgeStepper watches these requests and checks whether a particular domain is involved in delivering software updates. If EdgeStepper recognizes an update-related domain, it interferes and redirects the request to a server controlled by PlushDaemon. The victim sees no warning sign because the update process appears completely normal. However, instead of downloading a legitimate update from the software provider, the victim unknowingly receives a malicious file from the attackers’ infrastructure. This deceptive update carries the first stage of a layered malware chain. The initial file is a Windows component known as LittleDaemon. It is intentionally disguised as a DLL file to convince the system that it is a harmless library file. Once LittleDaemon runs, it connects to one of the attacker-controlled nodes and downloads the next stage, known as DaemonicLogistics. This second-stage tool is decrypted and executed directly in memory, which makes it more difficult for traditional security products to spot because it avoids writing visible files to disk. DaemonicLogistics is essentially the bridge that loads the final and most important payload. The last payload is the group’s advanced backdoor, SlowStepper. This backdoor has been documented in earlier incidents, including a case in which users of a South Korean VPN service unknowingly received a trojanized installer from what appeared to be the vendor’s official site. SlowStepper gives the attackers broad access to a compromised machine. It can gather system information, execute various commands, browse and manipulate files, and activate additional spyware tools. Many of these tools are written in Python and are designed to steal browser data, capture keystrokes, and extract stored credentials, giving PlushDaemon a detailed picture of the victim’s activity. ESET researchers also examined the group’s interference with update traffic for Sogou Pinyin, which is one of the most widely used Chinese input software products. While this example helps illustrate the group’s behavior, the researchers observed similar hijacking patterns affecting other software products as well. This means PlushDaemon is not focused on one specific application but is instead targeting any update system they can manipulate through the network devices they have compromised. Because their technique relies on controlling the network path rather than exploiting a flaw inside the software itself, the group’s approach could be applied to targets anywhere in the world. The research report includes extensive technical information on every component uncovered in this campaign and offers indicators of compromise for defenders, including associated files, domains, and IP addresses. These findings suggest how imperative it is that a routine process like installing updates can become a highly effective attack vector when network infrastructure is tampered with. The case also reinforces the importance of securing routers and keeping administrator credentials strong, since a compromised device at the network level allows attackers to alter traffic without the user noticing any warning signs.
dlvr.it
December 1, 2025 at 4:04 AM
China's 'PlushDaemon' Hackers Infect Routers to Hijack Software Updates
China's 'PlushDaemon' Hackers Infect Routers to Hijack Software Updates
www.darkreading.com
November 30, 2025 at 12:40 AM
📌 Chinese Cyberespionage Group PlushDaemon Exploits Software Updates with EdgeStepper Malware https://www.cyberhub.blog/article/16010-chinese-cyberespionage-group-plushdaemon-exploits-software-updates-with-edgestepper-malware
Chinese Cyberespionage Group PlushDaemon Exploits Software Updates with EdgeStepper Malware
The Chinese cyberespionage group PlushDaemon has been identified by ESET researchers as utilizing a malware strain named EdgeStepper to intercept software update traffic. This operation aims to compromise supply chains by exploiting the software update processes of targeted organizations. While specific technical details and the full extent of the impact remain undisclosed, the nature of the attack underscores significant risks to supply chain integrity. Supply chain attacks are particularly insidious due to their potential to affect a broad user base through a single compromised source. By intercepting and potentially altering software updates, attackers can distribute malware to all users who install the compromised updates. This method leverages the inherent trust users place in software vendors, making it an effective vector for large-scale infections. The technical implications of this attack are profound. Organizations must ensure the integrity of their software update mechanisms. This includes verifying digital signatures, monitoring network traffic for unusual patterns, and employing endpoint detection and response (EDR) solutions to detect and mitigate such threats. The involvement of a state-sponsored group like PlushDaemon suggests a high level of sophistication and targeting, necessitating advanced defensive measures. From a broader cybersecurity perspective, this incident highlights the critical need for robust supply chain security. Vendors must implement stringent security measures to protect their update mechanisms from compromise. Organizations should also enhance their threat intelligence capabilities to stay abreast of emerging threats and respond effectively. In conclusion, the PlushDaemon group's use of EdgeStepper malware to intercept software updates represents a significant threat to supply chain security. Organizations must adopt a multi-layered defense strategy to detect, prevent, and respond to such sophisticated attacks.
www.cyberhub.blog
November 26, 2025 at 10:40 AM
ESET: grupo PlushDaemon, alinhado com a China, “ataca” routers.
ESET: grupo PlushDaemon, alinhado com a China, "ataca" routers
Redirecionamento de consultas DNS para um servidor DNS externo "malicioso" realizado ao nível dos routers.
pplware.sapo.pt
November 26, 2025 at 8:03 AM
“Análise: Como o grupo PlushDaemon, alinhado com a China, está transformando a segurança dos routers” #Tecnologia #Reviews #Gadgets #Portugal

Introdução Recentemente, investigadores da ESET identificaram um novo vetor de ataque do grupo cibercriminoso PlushDaemon, claramente ligado a interesses na…
“Análise: Como o grupo PlushDaemon, alinhado com a China, está transformando a segurança dos routers” #Tecnologia #Reviews #Gadgets #Portugal
Introdução Recentemente, investigadores da ESET identificaram um novo vetor de ataque do grupo cibercriminoso PlushDaemon, claramente ligado a interesses na China. Este grupo utiliza um implante chamado EdgeStepper, desconhecido até então, para vulnerar dispositivos de rede, como routers. A técnica empregada é conhecida como ataque 'man-in-the-middle', que permite ao invasor interceptar e manipular comunicações. Análise: Redirecionamento de Consultas DNS O EdgeStepper atua redirecionando todas as consultas DNS para um servidor externo malicioso. Este servidor, por sua vez, responde com endereços que sequestram atualizações de software. A estratégia usada por PlushDaemon visa efetivamente direcionar tráfego de atualizações para uma infraestrutura controlada pelo invasor.
hotnews.pt
November 26, 2025 at 1:05 AM
But where most APTs use edge devices as initial entry points to deeper network compromise, researchers at ESET have found that PlushDaemon uses them in its own way.
November 25, 2025 at 1:01 PM
"PlushDaemon" is one such group that has quietly, for quite a while now, been taking its own approach to the update hijack. Like Chinese advanced persistent threats (APTs) often do, it infects organizations through their edge devices.
November 25, 2025 at 1:00 PM
PlushDaemon compromises network devices for adversary-in-the-middle attacks www.welivesecurity.com/en/eset-rese...
PlushDaemon compromises network devices for adversary-in-the-middle attacks
ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks.
www.welivesecurity.com
November 25, 2025 at 8:42 AM
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates thehackernews.com/2025/11/edge...
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates
PlushDaemon hijacks software updates using EdgeStepper to redirect DNS traffic and deploy SlowStepper malware.
thehackernews.com
November 24, 2025 at 1:12 PM
China’s PlushDaemon APT has been hijacking software updates by infecting routers since 2018. They intercept DNS, reroute update checks, and drop a full backdoor. Edge devices are the weakest link. If you ignore your routers, attackers will not.
November 24, 2025 at 12:41 PM
PlushDaemon Deploys New PlushImp Backdoor in China-Aligned Spy Campaigns

China-aligned hacking group PlushDaemon is using a new C++ backdoor, PlushImp, in espionage campaigns targeting government entities in Southeast Asia.
PlushDaemon Deploys New PlushImp Backdoor in China-Aligned Spy Campaigns
China-aligned hacking group PlushDaemon is using a new C++ backdoor, PlushImp, in espionage campaigns targeting government entities in Southeast Asia.
concisecyber.com
November 24, 2025 at 11:45 AM
Feed: "Geek Feed"
By: geekfeed on Saturday, November 22, 2025
‘PlushDaemon’ hackers hijack software updates in supply-chain attacks
A China-linked threat actor tracked as 'PlushDaemon' is hijacking software update traffic using a new implant called EdgeStepper in cyberespionage operations. Since 2018, PlushDaemon hackers have targ...
geekfeed.net
November 22, 2025 at 9:47 PM
China's 'PlushDaemon' Hackers Infect Routers to Hijack Software Updates - www.darkreading.com/endpoint-sec...
China's 'PlushDaemon' APT Hijacks Software Updates
A unique take on the software update gambit has allowed the state-sponsored APT to evade attention as it mostly targets Chinese organizations.
www.darkreading.com
November 22, 2025 at 2:09 PM
China's state actors, PlushDaemon hackers are exploiting routers to perform software update hijacking predominantly against Chinese entities. This advanced persistent threat (APT) demonstrates soph0unded attack vectors requiring immediate attention for network defense.
November 21, 2025 at 5:06 PM
PlushDaemon compromete dispositivos de red en ataques adversary-in-the-middle

Vía: @esetofficial.bsky.social

www.welivesecurity.com/es/investiga...
November 21, 2025 at 3:36 PM
A unique take on the software update gambit has allowed "PlushDaemon" to evade attention as it mostly targets Chinese organizations. www.darkreading.com/endpoint-sec...
Chinese APT Infects Routers to Hijack Software Updates
A unique take on the software update gambit has allowed "PlushDaemon" to evade attention as it mostly targets Chinese organizations.
www.darkreading.com
November 21, 2025 at 1:18 PM
Chinese APT Infects Routers to Hijack Software Updates www.darkreading.com/endpoint-sec...
Chinese APT Infects Routers to Hijack Software Updates
A unique take on the software update gambit has allowed "PlushDaemon" to evade attention as it mostly targets Chinese organizations.
www.darkreading.com
November 21, 2025 at 1:00 PM