The group, engaged in cyberespionage operations, conducted an attack on the supply chain of a South Korean VPN developer, replacing the legitimate installer with one containing the SlowStepper backdoor, used exclusively by PlushDaemon
Researchers of ESET, a global European leader in the cybersecurity market, have discovered an attack on the supply chain of a VPN provider in South Korea by a previously undetected China-aligned APT group, which ESET has named PlushDaemon. In this cyberespionage operation, the attackers replaced the legitimate installer with one that also distributed the group's implant signature, called SlowStepper — a feature-rich backdoor with a toolkit of more than 30 components. The APT group has been active since at least 2019 and has conducted espionage operations against people and organizations in China, Taiwan, Hong Kong, South Korea, the United States and New Zealand.
"In May 2024, we noticed detections of malicious code in an NSIS installer for Windows that users in South Korea had downloaded from the website of the legitimate IPany VPN software. Upon further investigation, we discovered that the installer distributed both the legitimate software and the backdoor. We informed the developer of the VPN software of the compromise, and the malicious installer was removed from their website," says ESET researcher Facundo Muñoz, who made the discovery.
Furthermore, PlushDaemon is able to gain initial access via the technique of hijacking legitimate updates of Chinese applications, redirecting traffic to attacker-controlled servers. ESET also observed the group gaining access via vulnerabilities in legitimate web servers.
SlowStepper is a backdoor exclusively used by PlushDaemon, and is known for its multi-step C&C protocol using DNS, as well as the ability to download and run dozens of additional Python modules with spying functionality.
The malware collects a wide range of data from web browsers; is able to take photos; scan documents; collects information from various applications, including messaging applications (e.g., WeChat, Telegram); can spy via audio and video; and steals password credentials.
“The numerous components in PlushDaemon's toolset, and rich version history, show that, despite being previously unknown, this China-aligned APT group has worked relentlessly to develop a wide range of tools, making it a significant threat to watch,” concludes Muñoz.
For a detailed analysis and technical explanation of the PlushDaemon toolset, see the ESET Research blog post “China-aligned PlushDaemon compromises supply chain of Korean VPN service” on WeLiveSecurity.com and follow ESET Research On Twitter (now X) for updates on the latest news of the ESET search.






