A novel implant known as EdgeStepper is being used in cyberespionage activities by a China-affiliated threat actor known as “PlushDaemon” to intercept software update communications.
Since 2018, PlushDaemon hackers have used proprietary malware, like the SlowStepper backdoor, to attack people and organizations in the US, China, Taiwan, Hong Kong, South Korea, and New Zealand.
Universities, a Japanese car manufacturing facility in Cambodia, and electronics corporations have all been compromised by PlushDaemon. According to telemetry data from cybersecurity company ESET, the threat actor has been using malicious upgrades to compromise target networks since 2019.
After installing the EdgeStepper implant and gaining access to routers through known vulnerabilities or weak admin passwords read more about ‘PlushDaemon’ hackers hijack software updates in supply-chain attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
