Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors PlushDaemon

Also known as: Storm-0978, Tropical Scorpius, APT34, Smoke Sandstorm, TA455, Yellow Liderc, Earth Preta, Stately Taurus, tracked as, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, APT28, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, Nascent Ursa, Nodaria, FROZENVISTA, Storm-0587, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, Imperial Kitten, CASCADE PANDA, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, TA456, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, ETHEREAL PANDA, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER

Description

PlushDaemon operates with a clear emphasis on surveillance and data exfiltration. The group regularly targets legitimate software supply chains—most notably compromising the installer distribution of a Korean VPN provider—to plant its custom backdoor, SlowStepper, which contains more than thirty modular components for persistence, lateral movement, and credential theft. The attack surface is expanded through content injection attacks that hijack application update traffic via vulnerable web servers (e.g., Apache HTTP Server), ensuring that the malicious payload is delivered under the guise of legitimate updates. These injections are frequently coupled with DNS TXT record manipulation and fallback IP resolution to maintain resilient command‑and‑control channels. PlushDaemon also conducts ad‑in‑the‑middle campaigns by compromising routers or DNS settings, enabling it to subvert the update mechanisms of victim systems. For execution, it employs DLL side‑loading through the legitimate Visual Studio utility regcap.exe, runs signed malicious modules (soc.mod, stoll.mod), and exploits vulnerabilities such as CVE‑2018‑6065 in browsers to inject JavaScript that grants remote code execution. Once on a victim network, the actor deploys additional backdoors—including LittleDaemon, DaemonicLogistics, and EdgeStepper—often through web shells or misconfigured services like Microsoft Exchange (via ProxyShell exploits) and PostgreSQL. These implants are capable of exfiltrating credentials with tools such as Mimikatz and launching obfuscated PowerShell loaders that establish Cobalt Strike beacons for further lateral activity.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Manufacturing
Energy
Education
Transportation
Non profit
Critical infrastructure
Aerospace
Healthcare
Think tank
Media
Maritime
Pharmaceutical
Food agriculture
Aviation
Chemical
Utilities
Construction
Entertainment
Legal services
Retail
Nuclear
Hospitality
Oil gas
Information technology

Targeted Countries / Regions

CN
RU
US
UA
KR
IL
TW
AE
BY
IR
IN
PK
JP
VN
PL
LB
TR
DE
KZ
FR
EG
KP
IQ
IT
SA
CA
GB
BR
MX

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

PlushDaemon is an advanced threat group aligned with China that carries out supply‑chain attacks, content injection, and ad‑in‑the‑middle techniques to compromise a wide range of sectors worldwide. The actor leverages legitimate software updates, signed modules, and DLL side‑loading to deploy custom backdoors such as SlowStepper while using multi‑stage DNS‑based C2 channels for persistence and evasion. PlushDaemon’s operations indicate a high level of sophistication and an explicit focus on espionage against governments, critical infrastructure, and commercial enterprises.

Goals & Targeting

PlushDaemon’s strategic objectives appear centered on long‑term espionage against a broad target set encompassing government, defense, financial services, manufacturing, energy, communications, transportation, healthcare, aerospace, and critical infrastructure. By compromising supply chains and leveraging legitimate software distribution mechanisms, the actor can stealthily infiltrate high‑profile organizations across many geographies—including China, Taiwan, Korea, the United States, New Zealand, Russia, Israel, and beyond—collecting strategic intelligence while minimizing detection.

Enhanced Description

Key Capabilities

  • Supply chain compromise by trojanizing software installers
  • Content injection hijacking legitimate update traffic via compromised servers (Apache HTTP Server)
  • Multi‑stage command‑and‑control using DNS TXT records with fallback IP resolution
  • DLL side‑loading through regcap.exe and malicious lregdll.dll
  • Spear‑phishing with deceptive attachments or links that redirect to malicious sites
  • Redirect chains mimicking legitimate CDN providers such as Cloudflare
  • Browser exploitation (e.g., CVE‑2018‑6065)
  • Ad‐in‑the‑middle attacks hijacking router or DNS settings
  • Delivery and execution of custom backdoors (SlowStepper, LittleDaemon, DaemonicLogistics, EdgeStepper)
  • Web‑shell RCE via Microsoft Exchange ProxyShell exploits
  • Remote code execution through misconfigured PostgreSQL installations
  • Use of malicious archives (LNK/HTA) and weaponized DOCX files for initial access
  • In‑memory obfuscated PowerShell loaders deploying Cobalt Strike beacons
  • Use of signed malicious modules (soc.mod, stoll.mod)
  • Execution via Windows Command Shell and Python console commands

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. www.eset.com — Cited by web research for: Storm-0978
  2. www.welivesecurity.com — Cited by web research for: T1583.001
  3. www.welivesecurity.com — Cited by web research for: Payload
  4. apt.etda.or.th — Cited by web research for: Void
  5. ics-cert.kaspersky.com — Cited by web research for: GoRed
  6. www.eset.com — Cited by web research for: Egypt

Intel Summary

40

Techniques

62

Tools

7

Campaigns

55

IOCs

0

Observed Data

9

Tactics

Tags

APT
Supply Chain Attack
Backdoor / C2
China-aligned
Cyberespionage
Supply chain attack
State-sponsored

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.