logo

PlushDaemon compromises network devices for adversary-in-the-middle attacks

ID: 4df3aaee-11db-53c5-a1c1-6366b129d11e

STIX ID: report--4df3aaee-11db-53c5-a1c1-6366b129d11e

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2025-11-19

Date Updated: 2026-05-01

...
...

ESET details PlushDaemon, a China-aligned APT that compromises network devices to deploy a Go-based MIPS implant (EdgeStepper) which redirects DNS queries to attacker-controlled nodes to hijack legitimate software updates; those updates deliver LittleDaemon and DaemonicLogistics which install the SlowStepper backdoor on Windows systems. The report includes technical analysis of the implants and downloaders, IoCs (file hashes, domains, IPs), victim distribution, and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.