Researchers have uncovered new details on the China-aligned threat actor PlushDaemon, which has been active since at least 2018 and is responsible for sophisticated espionage campaigns across the Asia-Pacific and Western regions.
The group targets individuals and organizations in China, Taiwan, Hong Kong, Cambodia, South Korea, the United States, and New Zealand, using a custom backdoor, SlowStepper, and an adversary-in-the-middle (AitM) tool, EdgeStepper.
EdgeStepper Enables Update Hijacking
EdgeStepper is a malicious network implant that intercepts DNS traffic and redirects legitimate software update requests to attacker-controlled servers.
Developed in using the GoFrame framework, EdgeStepper typically runs on compromised routers or network devices using the MIPS32 architecture.
It obtains configuration settings from an encrypted file and listens on port 1090, redirecting DNS requests from port 53 to a malicious DNS node controlled by PlushDaemon.

The implant manipulates traffic for popular Chinese software, such as Sogou Pinyin, by spoofing update domains, such as info.pinyin.sogou.com. Once a user’s system requests a legitimate update, EdgeStepper redirects traffic to a hijacking node that delivers malicious files instead.
This redirection allows PlushDaemon to provide the following stages of its attack chain without the victim’s knowledge.
PlushDaemon operators gain access by exploiting vulnerabilities in network device firmware or through weak administrative credentials. Once access is secured, EdgeStepper deploys iptables rules to control and proxy DNS requests.
The malicious DNS nodes then redirect users to hijacking servers that deliver trojanized updates disguised as legitimate software patches.
From LittleDaemon to SlowStepper
The attack chain involves several payloads working in sequence. When the compromised update is installed, a DLL file named LittleDaemon is delivered.
This file does not maintain persistence; instead, it contacts the hijacking node to download an intermediate downloader called DaemonicLogistics.
DaemonicLogistics executes directly in memory and retrieves the main backdoor, SlowStepper, which establishes persistence and provides remote access capabilities.
Communication is primarily performed through hijacked domains such as ime.sogou.com or mobads.baidu.com, making detection more difficult.
Telemetry from ESET shows that PlushDaemon’s campaign has affected victims since 2019, including targets in the United States, Taiwan, China, Hong Kong, New Zealand, and Cambodia. Notably, the group carried out a supply chain compromise of a South Korean VPN service in 2023, expanding its espionage reach.
Security researchers warn that PlushDaemon’s use of network implants such as EdgeStepper represents a growing trend among state-linked actors seeking to intercept and weaponize legitimate update mechanisms, enabling stealthy global operations with minimal visibility.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates