China-linked hacker group targets victims in East Asia with malicious VPN installers
ID: 75501146-fd32-56d5-88f1-b33e25fdde41
STIX ID: report--75501146-fd32-56d5-88f1-b33e25fdde41
Feed Name: The Record from Recorded Future News
Researchers reported that a China-aligned APT dubbed PlushDaemon compromised the legitimate Windows installer for South Korean VPN developer IPany in 2023, replacing it with a malicious installer that deployed a backdoor capable of extensive data collection and spying (including audio and video). ESET discovered the compromise after detecting the malicious installer downloaded from IPany’s website, observed victims within semiconductor and software company networks in South Korea, and identified activity affecting users in Japan and China; the group has an observed history of espionage since at least 2019.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
