Chinese APT Group Hijacks South Korean VPN, Unleashes Powerful 30-Module Backdoor


China-Linked APT Group PlushDaemon Targets South Korean VPN Provider

A newly discovered Chinese advanced persistent threat (APT) group, dubbed PlushDaemon, has been identified conducting a sophisticated supply chain attack against a South Korean VPN provider in 2023. Security researchers at ESET uncovered the operation, which involved replacing legitimate software with a compromised version containing a powerful backdoor named SlowStepper.

Key Findings:

– PlushDaemon has been active since 2019, targeting organizations in China, Taiwan, Hong Kong, South Korea, the USA, and New Zealand
– The group’s primary tool, SlowStepper, is a sophisticated backdoor with over 30 modules written in C++, Python, and Go
– The attack compromised IPany VPN’s installer, potentially affecting multiple organizations including a semiconductor company

Technical Details:

The SlowStepper backdoor features:
– Multiple stages of execution using complex persistence mechanisms
– DNS-based command and control infrastructure
– Extensive surveillance capabilities including audio/video recording
– Data theft modules targeting browsers, messaging apps, and system information
– Version history from 0.1.7 (2019) to 0.2.12 (2024)

The malware’s capabilities include:
– System information gathering
– Remote command execution
– File system manipulation
– Browser data harvesting
– Screen recording
– Wireless network information theft

The attack demonstrates sophisticated supply chain compromise techniques and represents a significant threat to organizations worldwide. The discovery of PlushDaemon adds another player to the list of state-sponsored threat actors requiring careful monitoring by security professionals.

Share This Article