#SlowStepper
#ESETresearch discovered + named 🇨🇳 China-aligned #APT group #PlushDaemon who did a supply-chain compromise of a 🇰🇷 South Korean #VPN provider, trojanizing its legitimate software installer with a Windows backdoor we named #SlowStepper www.welivesecurity.com/en/eset-rese...
🧵1/6
January 22, 2025 at 8:50 AM
🚨 PlushDaemon, a China-linked APT targeting S. Korea with a SlowStepper backdoor, SlowStepper. Using a supply chain attack, it infiltrates #VPN software to steal sensitive data.

Read: hackread.com/chinese-plus...

#CyberSecurity #PlushDaemon #APT #SlowStepper
Chinese PlushDaemon APT Targets S. Korean IPany VPN with Backdoor
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
January 23, 2025 at 8:45 PM
韓國VPN業者IPany遭駭,攻擊者在原廠提供安裝檔上加料以散布惡意程式SlowStepper www.ithome.com.tw/news/167133
韓國VPN業者IPany遭駭,攻擊者在原廠提供安裝檔上加料以散布惡意程式SlowStepper
資安業者ESET揭露韓國VPN服務業者IPany遭遇供應鏈攻擊的事故,中國駭客組織PlushDaemon於安裝程式加入惡意程式碼,導致部分使用者下載後電腦被植入名為SlowStepper的後門程式
www.ithome.com.tw
January 24, 2025 at 8:50 AM
In May 2024, Chinese hackers (PlushDemon) compromised IPany's website, deploying SlowStepper malware via a tainted installer targeting Asian users, possibly in semiconductor/software. The installer was later removed.#PlushDemonIPanyAttack
January 23, 2025 at 9:04 AM
When the software communicates with the hijacking node, it issues instructions to download an update for a DLL; in reality, the downloaders that we call LittleDaemon and DaemonicLogistics ultimately deploy the #SlowStepper backdoor. 3/5
November 19, 2025 at 10:12 AM
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates thehackernews.com/2025/11/edge...
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates
PlushDaemon hijacks software updates using EdgeStepper to redirect DNS traffic and deploy SlowStepper malware.
thehackernews.com
November 24, 2025 at 1:12 PM
#SlowStepper is a feature-rich backdoor with a toolkit of more than 30 components. We analyzed and documented it in a previous blogpost about the compromise of a South Korean VPN service provider. www.welivesecurity.com/en/eset-rese... 4/5
PlushDaemon compromises supply chain of Korean VPN service
ESET researchers uncover a supply-chain attack against a VPN provider in South Korea by a new China-aligned APT group we have named PlushDaemon.
www.welivesecurity.com
November 19, 2025 at 10:12 AM
The installer deploys malicious files that contain several components inside a custom-formatted archive , including loaders, a process monitor , legitimate PE files abused for side-loading, and the SlowStepper backdoor. 3/6
January 22, 2025 at 8:54 AM
The website had been compromised by PlushDaemon since at least November 2023, resulting in users from 🇰🇷 South Korea, 🇨🇳 China, and 🇯🇵 Japan downloading the trojanized installer, which deployed the legitimate software
and SlowStepper. 2/6
January 22, 2025 at 8:53 AM
TechNews ESET scopre il gruppo APT allineato alla Cina PlushDaemon
ESET scopre il gruppo APT allineato alla Cina PlushDaemon
l gruppo, impegnato in operazioni di cyberspionaggio, ha condotto un attacco alla supply chain di uno sviluppatore di VPN sudcoreano, sostituendo l'installer legittimo con uno contenente la backdoor SlowStepper, utilizzata esclusivamente da PlushDaemon
dlvr.it
January 28, 2025 at 6:07 PM
A previously undocumented China-aligned advanced persistent threat (APT) group named PlushDaemon has been linked to a supply chain attack targeting a South Korean virtual private network (VPN) provider in 2023, according to new findings from ESET.
thehackernews.com/2025/01/plus...
PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack
PlushDaemon APT targets South Korean VPN with SlowStepper backdoor. Multistage DNS C&C protocol aids espionage.
thehackernews.com
January 22, 2025 at 11:33 AM
Notícia da BleepingComputer

"IPany VPN comprometida em ataque à cadeia de suprimentos para impulsionar malware personalizado" #bolhasec
IPany VPN breached in supply-chain attack to push custom malware
South Korean VPN provider IPany was breached in a supply chain attack by the "PlushDaemon" China-aligned hacking group, who compromised the company's VPN installer to deploy the custom 'SlowStepper' m...
www.bleepingcomputer.com
January 25, 2025 at 4:30 PM
China-linked group called PlushDaemon using a tool named EdgeStepper to hijack internet routers :

EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates
thehackernews.com/2025/11/edge...
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates
PlushDaemon hijacks software updates using EdgeStepper to redirect DNS traffic and deploy SlowStepper malware.
thehackernews.com
November 19, 2025 at 10:10 AM
🚨 IPany VPN Breached in Supply-Chain Attack: Hackers Deploy SlowStepper Malware 🚨

WIRE TOR - The Ethical Hacking Services
South Korean VPN provider IPany fell victim to a sophisticated supply chain attack orchestrated by the China-aligned hacking group known as PlushDaemon. #hacker
January 22, 2025 at 6:42 PM
A previously undocumented China-aligned APT named PlushDaemon has been linked to a supply chain attack targeting a South Korean VPN)provider in 2023.

PlushDaemon is operational since at least 2019, China, Taiwan, Hong Kong, South Korea, the US and New Zealand.

thehackernews.com/2025/01/plus...
PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack
PlushDaemon APT targets South Korean VPN with SlowStepper backdoor. Multistage DNS C&C protocol aids espionage.
thehackernews.com
January 22, 2025 at 4:20 PM
PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack

A previously undocumented China-aligned advanced persistent threat (APT) group named PlushDaemon has been linked to a supply chain attack targeting a South Korean virtual private network (VPN) provider in 2023, according to…
PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack
A previously undocumented China-aligned advanced persistent threat (APT) group named PlushDaemon has been linked to a supply chain attack targeting a South Korean virtual private network (VPN) provider in 2023, according to new findings from ESET. "The attackers replaced the legitimate installer with one that also deployed the group's signature implant that we have named SlowStepper – a
shoebhakim.com
January 22, 2025 at 9:26 AM
SlowStepper has several interesting features such as decoding #DNS TXT records of a malicious domain to obtain its C&C servers, and a 🐚 shell mode with custom commands, one of which executes modules of an extensive toolkit stored at the Chinese code repository #GitCode. 4/6
January 22, 2025 at 8:56 AM
ESET found an ELF implant (bioset) dubbed EdgeStepper that redirects DNS from compromised routers to hijack software updates and deploy SlowStepper; downloaders LittleDaemon/DaemonicLogistics observed. #PlushDaemon #EdgeStepper #SlowStepper https://bit.ly/3LLDkUQ
November 19, 2025 at 3:00 PM
IPany VPN breached in supply-chain attack to push custom malware
IPany VPN breached in supply-chain attack to push custom malware
South Korean VPN provider IPany was breached in a supply chain attack by the "PlushDaemon" China-aligned hacking group, who compromised the company's VPN installer to deploy the custom 'SlowStepper' malware.
www.bleepingcomputer.com
January 22, 2025 at 3:32 PM