ESET found an ELF implant (bioset) dubbed EdgeStepper that redirects DNS from compromised routers to hijack software updates and deploy SlowStepper; downloaders LittleDaemon/DaemonicLogistics observed. #PlushDaemon #EdgeStepper #SlowStepper https://bit.ly/3LLDkUQ
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates reconbee.com/edgestepper-...
#EdgeStepper #DNSqueries #malware #malwareattack #hijacked #hijacking #cybersecurity #cyberattack
~Eset~
PlushDaemon deploys the EdgeStepper network implant to hijack software updates via adversary-in-the-middle attacks.
-
IOCs: 8. 212. 132. 120, 47. 242. 198. 250, ds20221202. dsc. wcsset. com
-
#EdgeStepper #PlushDaemon #ThreatIntel
iT4iNT SERVER EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates VDS VPS Cloud #CyberSecurity #Malware #DNSHijacking #PlushDaemon #EdgeStepper
#ESETresearch discovered and analyzed a previously undocumented malicious tool for network devices that we have named #EdgeStepper, enabling China-aligned #PlushDaemon APT to perform adversary-in-the-middle to hijack updates to deliver malware. www.welivesecurity.com/en/eset-rese... 1/5