logo

‘PlushDaemon’ hackers hijack software updates in supply-chain attacks

ID: 4a833aeb-294a-5c6e-9c37-2cf058d74a93

STIX ID: report--4a833aeb-294a-5c6e-9c37-2cf058d74a93

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-11-19

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

A China-linked APT called PlushDaemon is conducting supply‑chain style cyber‑espionage by compromising routers (via known vulnerabilities or weak credentials) and installing an ELF implant named EdgeStepper to hijack software-update traffic and deliver a multi-stage Windows payload (LittleDaemon → DaemonicLogistics → SlowStepper). ESET telemetry links these operations to sustained targeting of electronics manufacturers, universities, and other organizations across multiple countries, and the report includes technical details and IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.