PlushDaemon’s Silent Surge: Inside the Stealthy China-Linked Cyber Operation Hijacking Global Software Updates

Listen to this Post

Featured Image

Introduction

A quiet but dangerous cyber operation has been unfolding across the world, one that turns everyday software updates into secret entry points for espionage. PlushDaemon, a China-aligned threat actor active since 2018, has been refining a multilayered system that corrupts trusted update channels, compromises routers, and quietly slips custom backdoors into devices across multiple continents. The campaign blends technical innovation with strategic patience, targeting nations in the Asia-Pacific and the West, and using covert tools to hide malicious payloads inside what appear to be normal system patches. What follows is a closer look at how this hidden ecosystem works and why it marks a troubling evolution in global cyber operations.

Summary of the Original

PlushDaemon has emerged as a sophisticated cyber threat actor operating since at least 2018, conducting international espionage across China, Taiwan, Hong Kong, Cambodia, South Korea, the United States, and New Zealand. At the heart of its operations are two custom tools, SlowStepper and EdgeStepper. EdgeStepper is a specially designed network implant that intercepts DNS activity. It redirects legitimate software update traffic to attacker-controlled servers, essentially hijacking the update mechanism. This implant is built using the GoFrame framework and typically runs on compromised routers or network devices using the MIPS32 architecture.

EdgeStepper is configured through an encrypted file and listens on port 1090 while rerouting DNS traffic from port 53 to malicious DNS nodes under PlushDaemon’s control. It manipulates requests for popular Chinese software like Sogou Pinyin by spoofing update domains. When a user tries to download an update, the tool silently redirects the request to a hijacking node that delivers malicious files instead of legitimate updates.

Compromise usually begins with the attacker exploiting firmware vulnerabilities or abusing weak administrative passwords. Once they gain access, EdgeStepper installs iptables rules to monitor, reroute, and proxy DNS requests. These modified DNS nodes point the user toward hijacking servers that distribute trojanized updates disguised as trustworthy software patches.

Once the fake update is installed, the attack progresses through several payloads. A DLL called LittleDaemon is delivered first, and although it does not maintain persistence, it contacts the hijacking node to download an in-memory loader named DaemonicLogistics. This loader retrieves the main backdoor, SlowStepper, which maintains persistence and enables remote access to the compromised system.

The communication between these components routes through hijacked domains such as ime.sogou.com or mobads.baidu.com, making the activity difficult to identify through normal traffic analysis. Telemetry from ESET confirms the group’s operations have been affecting victims since 2019 and includes a notable supply chain compromise of a South Korean VPN provider in 2023. Security researchers warn that PlushDaemon’s reliance on network implants like EdgeStepper demonstrates an increasing trend among nation-state groups to infiltrate legitimate update infrastructures, enabling long-term stealth with very little technical evidence on endpoint devices.

What Undercode Say:

PlushDaemon’s operational strategy reflects a wider shift in state-sponsored cyber campaigns. Instead of relying on malware alone, they are weaponizing trust. Software updates are one of the most widely accepted forms of system modification. Users rarely question them, and security tools often treat them as safe. PlushDaemon exploits this assumption by inserting itself into the update process rather than attacking the endpoint directly.

This creates a perfect storm. By living inside routers and network devices, especially those running MIPS-based firmware, PlushDaemon avoids detection from standard endpoint security. Traditional antivirus systems overlook traffic redirection at the router level, leaving entire organizations blind to what is happening before the data even reaches a computer. EdgeStepper’s use of DNS interception reveals a deep understanding of where digital trust truly resides. DNS serves as the backbone of how devices find update servers, and if that can be manipulated, nearly any software ecosystem becomes vulnerable.

What stands out is the modularity. LittleDaemon, DaemonicLogistics, and SlowStepper are not isolated tools. They operate as a synchronized chain, similar to modern supply chain malware techniques but with an added network layer twist. Each stage is small, focused, and designed to hand off responsibility to the next component, reducing the footprint at every step. This layered approach mirrors elite operations conducted by the most advanced threat actors in the world.

Another notable element is the targets. PlushDaemon casts a wide net, from the United States to South Korea and throughout the Asia-Pacific region. This suggests not an opportunistic hacker group but a strategic espionage effort aligned with geopolitical interests. Their compromise of a South Korean VPN service is especially telling. By accessing a provider used by thousands of citizens, diplomats, and corporations, PlushDaemon gains indirect visibility into countless communications.

The operator’s decision to disguise traffic through domains belonging to Baidu or Sogou adds another layer of camouflage. Many security teams ignore or whitelist traffic to these popular Chinese services, giving PlushDaemon a natural hiding place. It shows meticulous planning and an understanding of global traffic norms.

The long-term implications are significant. If attackers can routinely hijack update channels at the network level, every software company becomes a potential distribution platform for espionage tools. Nation-state actors will increasingly seek to control the infrastructure in between users and services instead of just targeting endpoints or servers. PlushDaemon’s campaign might represent the early stage of a new era in cyber operations, one where trusted pathways become weaponized corridors for silent infiltration.

This approach challenges defenders to rethink their strategies. Traditional perimeter defenses cannot detect router-level implants. Organizations must begin treating IoT devices, routers, and network appliances as high-risk assets rather than background hardware. Firmware audits, DNS anomaly detection, and strict update validation will become essential in preventing attacks like those launched by PlushDaemon.

Ultimately, PlushDaemon’s campaign is a warning. Espionage groups are no longer satisfied with exploiting vulnerabilities. They want to control the essential mechanics of the internet itself. Once they do, every update, every patch, and every connection becomes a potential trap.

Fact Checker Results

✅ PlushDaemon has been active since at least 2018

✅ EdgeStepper hijacks DNS requests to deliver malicious updates

❌ No evidence the group targets devices outside the listed Asia-Pacific and Western regions

Prediction

PlushDaemon is likely to expand its infrastructure across more countries, leveraging compromised routers and IoT devices to increase persistence and reduce the chance of detection. 🔍
State-aligned actors may adopt similar DNS-level hijacking methods as they recognize the strategic power of silent software update interception. 🌐
Organizations will face growing pressure to secure update pathways, leading to broader use of DNSSEC and authenticated update channels. 🛡️

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon