PlushDaemon APT Uses EdgeStepper Implant for Adversary-in-the-Middle Attacks
ESET researchers have uncovered a sophisticated cyberespionage campaign conducted by PlushDaemon, a China-aligned advanced persistent threat (APT) group active since 2018. The group utilizes a previously undocumented network implant named EdgeStepper to execute adversary-in-the-middle attacks. By compromising network devices such as routers, often through software vulnerabilities or weak credentials, PlushDaemon redirects DNS queries to malicious nodes. This technique effectively hijacks legitimate software update traffic, rerouting it to attacker-controlled infrastructure to deploy the SlowStepper backdoor on Windows machines. The analysis also details two downloaders, LittleDaemon and DaemonicLogistics, used in this process. Victimology data indicates that PlushDaemon has targeted individuals and organizations across multiple regions, including the United States, Taiwan, China, Hong Kong, New Zealand, and Cambodia. Recent victims include entities in the automotive and manufacturing sectors. This discovery highlights the group's evolving tactics, which also include supply-chain compromises and exploitation of web server vulnerabilities, posing significant risks to global cybersecurity infrastructure and software integrity.
Wire timeline
PlushDaemon APT Uses EdgeStepper Implant for Adversary-in-the-Middle Attacks
ESET researchers have uncovered a sophisticated cyberespionage campaign conducted by PlushDaemon, a China-aligned advanced persistent threat (APT) group active since 2018. The group utilizes a previously undocumented network implant named EdgeStepper to execute adversary-in-the-middle attacks. By compromising network devices such as routers, often through software vulnerabilities or weak credentials, PlushDaemon redirects DNS queries to malicious nodes. This technique effectively hijacks legitimate software update traffic, rerouting it to attacker-controlled infrastructure to deploy the SlowStepper backdoor on Windows machines. The analysis also details two downloaders, LittleDaemon and DaemonicLogistics, used in this process. Victimology data indicates that PlushDaemon has targeted individuals and organizations across multiple regions, including the United States, Taiwan, China, Hong Kong, New Zealand, and Cambodia. Recent victims include entities in the automotive and manufacturing sectors. This discovery highlights the group's evolving tactics, which also include supply-chain compromises and exploitation of web server vulnerabilities, posing significant risks to global cybersecurity infrastructure and software integrity.
WeLiveSecurity