Malware, Threat Intelligence, Supply chain

New EdgeStepper implant leveraged in PlushDaemon supply chain compromise

Privacy concept: pixelated words Malware on digital background, 3d render

Attacks with the new EdgeStepper implant have been deployed by the China-linked threat group PlushDaemon to facilitate software update traffic takeovers as part of a cyberespionage operation, according to BleepingComputer.

Initial router access via known vulnerabilities or weak admin credentials has allowed PlushDaemon to install the Golang-based EdgeStepper implant, which collects and redirects DNS queries to an illicit DNS node upon confirmation of a software updating domain, an analysis from ESET showed. Updating the software post-EdgeStepper installation prompts the delivery of the first-stage LittleDaemon malware loader, which subsequently retrieves and executes the DaemonicLogistics malware dropper.

PlushDaemon then leverages DaemonicLogistics to execute the SlowStepper backdoor, which allows system data gathering, file operation and command execution, and Python-based spyware delivery, said researchers, who noted the robustness of PlushDaemon's adversary-in-the-middle capabilities in enabling global compromise. Such a development comes after PlushDaemon was reported to have targeted universities, electronics manufacturers, and a Cambodia-based Japanese auto manufacturing facility.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds