China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware

A China-linked cyberespionage group allegedly exploited a legitimate VPN service to distribute malware and spy on victims’ activities. ESET’s security research team found the malicious code – as well as legitimate software – in the Windows installer of IPany, a South Korean VPN provider.

The PlushDaemon APT group is also known for hijacking legitimate Chinese app updates, but this technically advanced supply chain attack against a trusted Korean VPN company makes the hacking group “a significant threat to watch” , said ESET experts. .

The SlowStepper backdoor

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top