According to fresh research from ESET, a supply chain attack against a South Korean virtual private network (VPN) provider in 2023 was connected to PlushDaemon, an as-yet-unknown China-aligned advanced persistent threat (APT) group.
“In a technical report shared with The Hacker News, ESET researcher Facundo Muñoz stated that the attackers swapped out the legitimate installer with one that also installed the group’s signature implant, which we have named SlowStepper — a feature-rich backdoor with a toolkit of more than 30 components.”
Targeting people and organizations in China, Taiwan, Hong Kong, South Korea, the US, and New Zealand, PlushDaemon is seen as a China-nexus organization that has been active since at least 2019 read more about PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
