A China-aligned threat group known as PlushDaemon has been conducting sophisticated supply chain attacks by compromising network devices, particularly routers, to hijack software update mechanisms. Researchers from ESET discovered that the group deploys a custom implant called EdgeStepper on compromised devices, which intercepts and redirects DNS queries related to software updates to attacker-controlled infrastructure. This redirection enables PlushDaemon to deliver malicious payloads, including the downloaders LittleDaemon and DaemonicLogistics, which ultimately install the SlowStepper backdoor toolkit for cyberespionage. The campaign has targeted a wide range of organizations, including universities, electronics manufacturers, and automotive sector companies across the United States, Taiwan, Hong Kong, South Korea, New Zealand, and mainland China.
The attackers gain initial access by exploiting known vulnerabilities or weak administrative credentials on network devices. Once EdgeStepper is installed, it reroutes legitimate update traffic, allowing the attackers to deliver trojanized software updates and establish persistent access. The SlowStepper backdoor provides extensive espionage capabilities, enabling the collection of sensitive information from compromised systems. PlushDaemon has a history of leveraging supply chain attacks and has previously targeted users of the South Korean VPN product IPany. The ongoing campaign highlights the increasing use of adversary-in-the-middle techniques by China-affiliated APT groups to compromise global targets through trusted software update channels.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
On November 19, 2025, ESET published research describing PlushDaemon's use of the previously undocumented Go-based EdgeStepper implant to hijack DNS traffic on compromised network devices. The report detailed how the group redirected software update requests to attacker-controlled infrastructure to deliver LittleDaemon, DaemonicLogistics, and the SlowStepper backdoor.
Since 2019, PlushDaemon has used compromised routers and other edge devices to redirect DNS requests for legitimate software update domains to attacker-controlled infrastructure. Initial access to the network gear was achieved through known vulnerabilities or weak administrator passwords.
ESET assessed that the China-aligned threat actor PlushDaemon has been active since at least 2018, targeting organizations in Asia-Pacific and the United States. Victims included universities and manufacturing firms across countries such as the U.S., Taiwan, China, Hong Kong, New Zealand, and Cambodia.
Among the identified victims, PlushDaemon compromised a Japanese automotive manufacturing plant in Cambodia as part of its espionage activity. The intrusion was part of the broader campaign targeting organizations through hijacked update traffic.
ESET previously linked PlushDaemon to a supply-chain attack involving South Korean VPN provider IPany that delivered the SlowStepper implant. This earlier case connected the group to abuse of trusted software distribution channels.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
7 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcewelivesecurity.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.