logo

PlushDaemon compromises supply chain of Korean VPN service

ID: c0276710-ed09-5da9-b0e6-a8a7cd7e0635

STIX ID: report--c0276710-ed09-5da9-b0e6-a8a7cd7e0635

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2025-01-22

Date Updated: 2026-05-01

...
...

ESET reports that PlushDaemon, a China-aligned APT, performed a 2023 supply-chain compromise of the South Korean VPN IPany by replacing the legitimate installer with one that deployed SlowStepper — a feature-rich, multistage backdoor (C++ core plus ~30 Python/Go modules) capable of credential harvesting, audio/video capture, remote access, and broad data collection. The analysis covers deployment and persistence mechanisms (DLL side-loading, Run/Winlogon registry entries), C2 behavior (DNS TXT retrieval of AES-encrypted C2 lists and TCP channels), execution of remote Python modules, mapped MITRE ATT&CK techniques, and a comprehensive set of IoCs (files, domains, IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.