Tag: Reroutes DNS Queries

EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates
News

EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates

A previously unreported Go-based network backdoor nicknamed EdgeStepper has been seen to be used by the threat actor PlushDaemon to enable adversary-in-the-middle (AitM) assaults. According to a study shared with The Hacker News by ESET security researcher Facundo Muñoz, EdgeStepper efficiently reroutes traffic from legitimate infrastructure used for software updates to attacker-controlled infrastructure by rerouting all DNS queries to an external, malicious hijacking node. PlushDaemon is thought to be a China-aligned group that has been active since at least 2018 and has attacked organizations in the United States, New Zealand, Cambodia, Hong Kong, Taiwan, South Korea, and mainland China. The supply chain attack against a South Korean virtual private network (VPN) provider calle...