216.73.217.22

Supply chain of Korean VPN service compromised

· Published 22/01/2025 14:41 · Modified 22/01/2025 19:17

Export JSON

Essential information

Published
22/01/2025 14:41
Modified
22/01/2025 19:17
Tags
2025-01-22 apt backdoor china espionage slowstepper south korea supply-chain vpn
Related entities
1 intrusion sets (apt), 32 techniques (mitre), 1 malware, 8 others

Description

ESET researchers have uncovered a attack against a South Korean provider by a previously unknown -aligned group named PlushDaemon. The attackers replaced the legitimate installer with a malicious version that deployed their , a feature-rich implant with over 30 components. PlushDaemon has been active since at least 2019, targeting entities in , Taiwan, Hong Kong, , the US, and New Zealand. The group's main initial access vector is hijacking legitimate updates of Chinese applications. uses a multi-stage C&C protocol involving DNS queries and has an extensive toolkit of Python and Go modules for data collection and .

External references