Attacks with the new EdgeStepper implant have been deployed by the China-linked threat group PlushDaemon to facilitate software update traffic takeovers as part of a cyberespionage operation, according to BleepingComputer.Initial router access via known vulnerabilities or weak admin credentials has allowed PlushDaemon to install the Golang-based EdgeStepper implant, which collects and redirects DNS queries to an illicit DNS node upon confirmation of a software updating domain, an analysis from ESET showed. Updating the software post-EdgeStepper installation prompts the delivery of the first-stage LittleDaemon malware loader, which subsequently retrieves and executes the DaemonicLogistics malware dropper.PlushDaemon then leverages DaemonicLogistics to execute the SlowStepper backdoor, which allows system data gathering, file operation and command execution, and Python-based spyware delivery, said researchers, who noted the robustness of PlushDaemon's adversary-in-the-middle capabilities in enabling global compromise. Such a development comes after PlushDaemon was reported to have targeted universities, electronics manufacturers, and a Cambodia-based Japanese auto manufacturing facility.
Malware, Threat Intelligence, Supply chain
New EdgeStepper implant leveraged in PlushDaemon supply chain compromise
(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
