China’s PlushDaemon Group Uses EdgeStepper Implant to Infect Network Devices with SlowStepper Malware in Global Supply Chain Attacks



  • China-aligned PlushDaemon deploys malware via compromised routers
  • PlushDaemon implements LittleDaemon and DaemonLogistics on network devices
  • The final payload, SlowStepper, can execute commands and deploy spyware.

ESET has discovered that China-aligned hacking group PlushDaemon is targeting routers and other network devices with malware to launch supply chain attacks.

Cybersecurity experts note that the group has been active since 2018 and has so far deployed attacks against targets in the United States, New Zealand, Cambodia, Hong Kong, Taiwan and mainland China.

Leave a Comment

Your email address will not be published. Required fields are marked *