PlushDaemon APT Targeted South Korean VPN Software
ID: 2946f99f-e891-56de-bfb4-8dc8d0f00e79
STIX ID: report--2946f99f-e891-56de-bfb4-8dc8d0f00e79
Feed Name: Infosecurity Magazine (News)
Threat Score
PlushDaemon, a China-linked APT active since 2019, conducted a 2023 supply-chain compromise of the South Korean VPN installer IPany by embedding a feature-rich backdoor called SlowStepper (30+ modules) that enables data exfiltration, audio/video recording, and network reconnaissance; victims included South Korean semiconductor and software firms and individuals in China and Japan, and ESET’s disclosure led to the removal of the malicious installer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
