A newly discovered Chinese advanced persistent threat (APT) group, dubbed PlushDaemon, has been identified conducting a sophisticated supply chain attack against a South Korean VPN provider in 2023. Security researchers at ESET uncovered the operation, which involved replacing legitimate software with a compromised version containing a powerful backdoor named SlowStepper.
Key Findings:
– PlushDaemon has been active since 2019, targeting organizations in China, Taiwan, Hong Kong, South Korea, the USA, and New Zealand
– The group’s primary tool, SlowStepper, is a sophisticated backdoor with over 30 modules written in C++, Python, and Go
– The attack compromised IPany VPN’s installer, potentially affecting multiple organizations including a semiconductor company
Technical Details:
The SlowStepper backdoor features:
– Multiple stages of execution using complex persistence mechanisms
– DNS-based command and control infrastructure
– Extensive surveillance capabilities including audio/video recording
– Data theft modules targeting browsers, messaging apps, and system information
– Version history from 0.1.7 (2019) to 0.2.12 (2024)
The malware’s capabilities include:
– System information gathering
– Remote command execution
– File system manipulation
– Browser data harvesting
– Screen recording
– Wireless network information theft
The attack demonstrates sophisticated supply chain compromise techniques and represents a significant threat to organizations worldwide. The discovery of PlushDaemon adds another player to the list of state-sponsored threat actors requiring careful monitoring by security professionals.
