PlushDaemon Strikes Again: China’s Mischievous Hackers Unleash EdgeStepper Backdoor in Global Cyber Comedy

PlushDaemon, a China-aligned threat actor, is using EdgeStepper, a Go-based network backdoor, to stage AitM attacks. By rerouting DNS queries, they’re making software update channels as trustworthy as a used car salesman in a rainstorm. With victims ranging from universities to car companies, EdgeStepper is the latest cyber mischief-maker on the block.

Pro Dashboard

Hot Take:

In the thrilling world of cyber espionage, PlushDaemon is the James Bond of threat actors, except instead of martinis, they prefer coding in Go. EdgeStepper is their latest gadget, turning routers into secret agents and DNS queries into covert messages. Move over, 007; there’s a new player in town, and they’ve got a plush little daemon doing all the dirty work!

Key Points:

  • PlushDaemon is a China-aligned threat actor using a Go-based network backdoor called EdgeStepper for adversary-in-the-middle (AitM) attacks.
  • EdgeStepper hijacks DNS queries to redirect software update traffic to attacker-controlled nodes.
  • PlushDaemon has been active since at least 2018, attacking entities across the globe, including the U.S., South Korea, and Taiwan.
  • EdgeStepper consists of a Distributor module and Ruler component to manipulate IP filter rules using iptables.
  • SlowStepper, a feature-rich implant, aids in data extraction and system compromise once deployed by EdgeStepper.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?