logo

Chinese Cyberspies Target South Korean VPN in Supply Chain Attack

ID: 2c7e9446-9e6c-5f0d-8468-b8208bbae2bb

STIX ID: report--2c7e9446-9e6c-5f0d-8468-b8208bbae2bb

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-01-22

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

ESET researchers discovered a supply-chain compromise by a China-aligned APT named PlushDaemon that implanted a 'lite' variant of its SlowStepper backdoor into the Windows NSIS installer for South Korean VPN vendor IPany; the backdoor uses DNS-based multistage C2 and modular espionage tools (audio/video capture, data collection), infected victims in multiple countries (including South Korea, Japan, China), and ESET published IoCs and samples after notifying the vendor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.