China's 'PlushDaemon' Hackers Infect Routers to Hijack Software Updates
ID: 36a1f069-bdec-5e5d-a5e6-15b8037124e1
STIX ID: report--36a1f069-bdec-5e5d-a5e6-15b8037124e1
Feed Name: Dark Reading
PlushDaemon is a Chinese state-aligned APT active since at least 2018 that infects edge devices (often via vulnerabilities or default credentials) to perform man-in-the-middle hijacking of software update requests for popular Chinese applications; it uses a MIPS-based router implant called EdgeStepper to redirect victims to attacker infrastructure and delivers staged payloads culminating in the SlowStepper modular backdoor/infostealer which steals credentials, files, browser cookies and WeChat data. Victims have been mainly in mainland China and Hong Kong with some collateral targets elsewhere; recommended defenses focus on hardening and patching edge devices and securing device credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
