China-Linked Cyberespionage Group PlushDaemon Used South Korean VPN Service to Inject Malware


A China-linked cyber espionage group has reportedly exploited a legitimate VPN service to spread malware and spy on victims’ activities. ESET’s security research team found the malicious code (along with legitimate software) in the Windows installer from IPany, a South Korean VPN provider.

The so-called PlushDaemon APT group is also known to have hijacked legitimate Chinese app updates, but this technically advanced supply chain attack against a trusted Korean VPN company makes the hacking group “a significant threat to address.” pay attention,” said ESET experts. .

SlowStepper’s Back Door

Leave a Comment

Your email address will not be published. Required fields are marked *