Supply chain of Korean VPN service compromised
· Published 22/01/2025 14:41 · Modified 22/01/2025 19:17
Essential information
- Published
- 22/01/2025 14:41
- Modified
- 22/01/2025 19:17
- Tags
- 2025-01-22 apt backdoor china espionage slowstepper south korea supply-chain vpn
- Related entities
- 1 intrusion sets (apt), 32 techniques (mitre), 1 malware, 8 others
Description
ESET researchers have uncovered a supply-chain attack against a South Korean VPN provider by a previously unknown China-aligned APT group named PlushDaemon. The attackers replaced the legitimate VPN installer with a malicious version that deployed their SlowStepper backdoor, a feature-rich implant with over 30 components. PlushDaemon has been active since at least 2019, targeting entities in China, Taiwan, Hong Kong, South Korea, the US, and New Zealand. The group's main initial access vector is hijacking legitimate updates of Chinese applications. SlowStepper uses a multi-stage C&C protocol involving DNS queries and has an extensive toolkit of Python and Go modules for data collection and espionage.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 10:10 · Modified 21/12/2025 10:10
Techniques (MITRE) (32)
-
Browser Information Discovery
-
Video Capture
-
Peripheral Device Discovery
-
Obtain Capabilities
-
Stage Capabilities
-
Data Staged
-
Acquire Infrastructure
-
File and Directory Permissions Modification
-
Query Registry
-
Non-Application Layer Protocol
-
Screen Capture
-
Encrypted Channel
-
Indicator Removal
-
Hijack Execution Flow
-
Boot or Logon Autostart Execution
-
Software Discovery
-
Process Discovery
-
T1104
-
File and Directory Discovery
-
Application Layer Protocol
-
Automated Exfiltration
-
Remote Access Tools
-
Masquerading
-
Data Encoding
-
Obfuscated Files or Information
-
Subvert Trust Controls
-
Modify Registry
-
Exfiltration Over C2 Channel
-
Supply Chain Compromise
-
Exploit Public-Facing Application
-
Proxy
-
Command and Scripting Interpreter
Malware (1)
-
FamilyPublished 19/11/2025 21:09 · Modified 19/11/2025 21:09
Others (8)
- New Zealand
- Hong Kong
- Taiwan
- China
- Japan
- United States of America
- Semiconductor
- Technology