China’s PlushDaemon group uses EdgeStepper implant to infect network devices with SlowStepper malware in global supply chain attacks


  • China-tailored PlushDaemon deploys malware through compromised routers
  • PlushDaemon deploys LittleDaemon and DaemonLogistics on network devices
  • The final payload, SlowStepper, can run commands and deploy spyware

Chinese-aligned hacker group PlushDaemon has been discovered by ESET targeting routers and other network devices with malware to launch supply chain attacks.

The cyber security experts note that the group has been active since 2018 and has so far launched attacks against targets in the United States, New Zealand, Cambodia, Hong Kong, Taiwan and mainland China.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top