A new and highly sophisticated threat is emerging in the cybersecurity space, as the PlushDaemon – a malicious actor of Chinese origin – is leveraging a fresh implant called EdgeStepper to intercept and manipulate software update traffic in targeted attacks cyberespionage.

The group's operations are nothing new: since 2018, PlushDaemon has been targeting organizations in the US, China, Taiwan, Hong Kong, South Korea, and New Zealand, using custom malware such as the notorious SlowStepper. However, its new technique – compromising updates via router hijacking – raises the level of the threat.
Objectives and activity history
The profile of the targets clearly shows the group's focus on financial and technological sectors. Electronics manufacturers, academic institutions and even a Japanese car factory with a presence in Cambodia have been targeted.
See also: Sneaky 2FA Phishing Kit Adds BitB Pop-ups
According to ESET, PlushDaemon has been relying on malicious software updates to infiltrate networks since 2019. This tactic allows it to go almost unnoticed, as it “rides” processes that users fully trust.
How the attack chain works
The attack begins by compromising routers, usually through known vulnerabilities or simple, weak administrator passwords. Once the attackers gain control, they install the EdgeStepper.
EdgeStepper works by intercepting DNS queries. It checks if the domain in question is for a software update service and, if so, redirects the request to a malicious DNS server in the group. Essentially, the user thinks they are downloading a legitimate update, when in fact they are connecting directly to the PlushDaemon infrastructure.

At this stage, the victim receives a file that appears to be a DLL and is named popup_4.2.0.2246.dll. In reality, however, it is the LittleDaemon. LittleDaemon then drops a second malware dropper, DaemonicLogistics, which runs decrypted in memory. That in turn downloads and activates the group's main backdoor, the notorious SlowStepper.
See also: WhatsApp vulnerability exposed 3.5 billion phone numbers
What does SlowStepper do?
SlowStepper has appeared before, including in attacks against users of the South Korean VPN IPany, where users unknowingly downloaded trojanized installers from the provider's official website.
Its capabilities are extensive:
- collects detailed system data
- allows full file management
- executes commands remotely
- activates spyware tools written in Python
- intercepts keystrokes
- steals browser data and credentials
In simpler words: anyone who is infected essentially loses control of their system.
Why the update trapping technique is so dangerous
Software updates are one of the most basic security mechanisms for a system, but when hackers manage to get between the user and the update server, they gain an unparalleled advantage.
The method used by PlushDaemon:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- bypasses antivirus and endpoint security
- looks perfectly legitimate in the eyes of the systems
- exploits a process that no one questions
This explains why these types of attacks are considered among the most dangerous internationally at the moment.
See also: Princeton University reveals data breach

What does this mean for businesses and users?
ESET experts emphasize that organizations should prioritize the security of routers and edge devices, as they are the first point of entry for the attack chain.
Recommended:
- firmware update
- disable default credentials
- use of strong passwords and MFA
- monitoring DNS traffic for suspicious redirects
For ordinary users, paying attention to updates and installing patches from official sources is crucial. In the world of modern cyber espionage, an attack can start with something as simple as a “Check for updates.”
Source: www.bleepingcomputer.com
