Advertisement · 728 × 90
#
Hashtag
#SlowStepper
Advertisement · 728 × 90

ESET found an ELF implant (bioset) dubbed EdgeStepper that redirects DNS from compromised routers to hijack software updates and deploy SlowStepper; downloaders LittleDaemon/DaemonicLogistics observed. #PlushDaemon #EdgeStepper #SlowStepper https://bit.ly/3LLDkUQ

0 0 0 0
Preview
PlushDaemon compromises supply chain of Korean VPN service ESET researchers uncover a supply-chain attack against a VPN provider in South Korea by a new China-aligned APT group we have named PlushDaemon.

#SlowStepper is a feature-rich backdoor with a toolkit of more than 30 components. We analyzed and documented it in a previous blogpost about the compromise of a South Korean VPN service provider. www.welivesecurity.com/en/eset-rese... 4/5

4 1 1 0
Post image

When the software communicates with the hijacking node, it issues instructions to download an update for a DLL; in reality, the downloaders that we call LittleDaemon and DaemonicLogistics ultimately deploy the #SlowStepper backdoor. 3/5

2 0 1 0
Preview
Chinese PlushDaemon APT Targets S. Korean IPany VPN with Backdoor Follow us on Bluesky, Twitter (X) and Facebook at @Hackread

🚚 PlushDaemon, a China-linked APT targeting S. Korea with a SlowStepper backdoor, SlowStepper. Using a supply chain attack, it infiltrates #VPN software to steal sensitive data.

Read: hackread.com/chinese-plus...

#CyberSecurity #PlushDaemon #APT #SlowStepper

3 1 0 0
Preview
IPany VPN breached in supply-chain attack to push custom malware South Korean VPN provider IPany was breached in a supply chain attack by the "PlushDaemon" China-aligned hacking group, who compromised the company's VPN installer to deploy the custom 'SlowStepper'


IPany VPN がサプラむチェヌン攻撃で䟵害され、カスタムマルりェアが拡散される

IPany VPN breached in supply-chain attack to push custom malware #BleepingComputer (Jan 22)

#IPany #PlushDaemon #SlowStepper #サプラむチェヌン攻撃 #VPNセキュリティ

0 0 0 0

#ESETresearch discovered + named 🇚🇳 China-aligned #APT group #PlushDaemon who did a supply-chain compromise of a 🇰🇷 South Korean #VPN provider, trojanizing its legitimate software installer with a Windows backdoor we named #SlowStepper www.welivesecurity.com/en/eset-rese...
🧵1/6

17 14 1 2