logo

PlushDaemon APT Targeted South Korean VPN Software

ID: 2946f99f-e891-56de-bfb4-8dc8d0f00e79

STIX ID: report--2946f99f-e891-56de-bfb4-8dc8d0f00e79

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2025-01-22

Date Updated: 2026-04-22

...
...

PlushDaemon, a China-linked APT active since 2019, conducted a 2023 supply-chain compromise of the South Korean VPN installer IPany by embedding a feature-rich backdoor called SlowStepper (30+ modules) that enables data exfiltration, audio/video recording, and network reconnaissance; victims included South Korean semiconductor and software firms and individuals in China and Japan, and ESET’s disclosure led to the removal of the malicious installer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.