PlushDaemon is a China-aligned advanced persistent threat group engaged in cyber-espionage and active since at least 2018. The group has targeted organizations and individuals across China, Hong Kong, Taiwan, Cambodia, South Korea, New Zealand, and the United States, including universities and manufacturing entities. PlushDaemon is associated with a 2023 supply-chain compromise affecting a South Korean VPN provider and has also exploited web server vulnerabilities and weak or default credentials on network devices. A defining PlushDaemon tradecraft element is adversary-in-the-middle intrusion activity centered on compromised routers, gateways, and other network devices. The group deploys the Go-based network implant EdgeStepper to redirect DNS traffic and hijack legitimate software-update flows, enabling malicious payload delivery with minimal victim-visible artifacts. This technique has been used both for initial access and for movement within compromised environments. PlushDaemon has abused update mechanisms for widely used Chinese software, including Sogou Pinyin, to deliver staged malware. Its Windows toolchain includes the downloaders LittleDaemon and DaemonicLogistics and the custom backdoor SlowStepper. DaemonicLogistics has been linked to in-memory loading and process-injection style execution, while related malware uses obfuscated API resolution, encrypted payloads, and custom PE loading to evade userland monitoring and conventional endpoint defenses. Malware associated with PlushDaemon commonly uses masquerading and encrypted or obfuscated components to reduce detection. PlushDaemon is widely assessed as operating in support of Chinese state interests, with espionage as its dominant mission. Known associated malware and subcomponents include EdgeStepper, LittleDaemon, DaemonicLogistics, and SlowStepper.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor associated with use of the DaemonicLogistics toolset; the article links the analyzed binary to PlushDaemon based on shared PDB path structure and the same GIF magic pattern.
Actor using EdgeStepper implant to reroute DNS and hijack software update traffic for adversary-in-the-middle delivery of malware.
China-aligned APT conducting a supply-chain compromise of a South Korean VPN provider by trojanizing an installer to deploy the SlowStepper implant.
PlushDaemon implants routers and network devices with EdgeStepper malware to hijack DNS, intercept update traffic, and deploy multi-stage backdoors for espionage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.