216.73.217.22

Network devices compromised for adversary-in-the-middle attacks

· Published 19/11/2025 21:09 · Modified 20/11/2025 10:01

Export JSON

Essential information

Published
19/11/2025 21:09
Modified
20/11/2025 10:01
Tags
2025-11-19 adversary-in-the-middle apt china daemoniclogistics dns hijacking edgestepper espionage littledaemon network implant slowstepper software update hijacking
Related entities
4 observables, 1 intrusion sets (apt), 4 malware, 10 others

Description

-aligned threat actor PlushDaemon has been conducting operations since 2018, targeting entities in , Taiwan, Hong Kong, Cambodia, South Korea, the United States, and New Zealand. The group employs a custom backdoor called and uses a named to hijack legitimate updates. redirects DNS queries to a malicious node, rerouting traffic from legitimate infrastructure to attacker-controlled servers. The group has also exploited web server vulnerabilities and performed a supply-chain attack. PlushDaemon's technique involves compromising network devices, deploying , and using it to redirect DNS queries for software updates to malicious nodes. This allows them to serve malicious updates containing the downloader, which then deploys the implant.

External references