PlushDaemon compromises supply chain of Korean VPN service
ID: c0276710-ed09-5da9-b0e6-a8a7cd7e0635
STIX ID: report--c0276710-ed09-5da9-b0e6-a8a7cd7e0635
Feed Name: WeLiveSecurity (ESET Research)
ESET reports that PlushDaemon, a China-aligned APT, performed a 2023 supply-chain compromise of the South Korean VPN IPany by replacing the legitimate installer with one that deployed SlowStepper — a feature-rich, multistage backdoor (C++ core plus ~30 Python/Go modules) capable of credential harvesting, audio/video capture, remote access, and broad data collection. The analysis covers deployment and persistence mechanisms (DLL side-loading, Run/Winlogon registry entries), C2 behavior (DNS TXT retrieval of AES-encrypted C2 lists and TCP channels), execution of remote Python modules, mapped MITRE ATT&CK techniques, and a comprehensive set of IoCs (files, domains, IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
