A previously unreported Go-based network backdoor nicknamed EdgeStepper has been seen to be used by the threat actor PlushDaemon to enable adversary-in-the-middle (AitM) assaults.
According to a study shared with The Hacker News by ESET security researcher Facundo Muñoz, EdgeStepper efficiently reroutes traffic from legitimate infrastructure used for software updates to attacker-controlled infrastructure by rerouting all DNS queries to an external, malicious hijacking node.
PlushDaemon is thought to be a China-aligned group that has been active since at least 2018 and has attacked organizations in the United States, New Zealand, Cambodia, Hong Kong, Taiwan, South Korea, and mainland China.
The supply chain attack against a South Korean virtual private network (VPN) provider called IPany, which targets a semiconductor company read more about EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
