Also known as: Storm-0978, Tropical Scorpius, APT34, Smoke Sandstorm, TA455, Yellow Liderc, Earth Preta, Stately Taurus, tracked as, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, APT28, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, Nascent Ursa, Nodaria, FROZENVISTA, Storm-0587, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, Imperial Kitten, CASCADE PANDA, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, TA456, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, ETHEREAL PANDA, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER
PlushDaemon operates with a clear emphasis on surveillance and data exfiltration. The group regularly targets legitimate software supply chains—most notably compromising the installer distribution of a Korean VPN provider—to plant its custom backdoor, SlowStepper, which contains more than thirty modular components for persistence, lateral movement, and credential theft. The attack surface is expanded through content injection attacks that hijack application update traffic via vulnerable web servers (e.g., Apache HTTP Server), ensuring that the malicious payload is delivered under the guise of legitimate updates. These injections are frequently coupled with DNS TXT record manipulation and fallback IP resolution to maintain resilient command‑and‑control channels. PlushDaemon also conducts ad‑in‑the‑middle campaigns by compromising routers or DNS settings, enabling it to subvert the update mechanisms of victim systems. For execution, it employs DLL side‑loading through the legitimate Visual Studio utility regcap.exe, runs signed malicious modules (soc.mod, stoll.mod), and exploits vulnerabilities such as CVE‑2018‑6065 in browsers to inject JavaScript that grants remote code execution. Once on a victim network, the actor deploys additional backdoors—including LittleDaemon, DaemonicLogistics, and EdgeStepper—often through web shells or misconfigured services like Microsoft Exchange (via ProxyShell exploits) and PostgreSQL. These implants are capable of exfiltrating credentials with tools such as Mimikatz and launching obfuscated PowerShell loaders that establish Cobalt Strike beacons for further lateral activity.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
PlushDaemon is an advanced threat group aligned with China that carries out supply‑chain attacks, content injection, and ad‑in‑the‑middle techniques to compromise a wide range of sectors worldwide. The actor leverages legitimate software updates, signed modules, and DLL side‑loading to deploy custom backdoors such as SlowStepper while using multi‑stage DNS‑based C2 channels for persistence and evasion. PlushDaemon’s operations indicate a high level of sophistication and an explicit focus on espionage against governments, critical infrastructure, and commercial enterprises.
Goals & Targeting
PlushDaemon’s strategic objectives appear centered on long‑term espionage against a broad target set encompassing government, defense, financial services, manufacturing, energy, communications, transportation, healthcare, aerospace, and critical infrastructure. By compromising supply chains and leveraging legitimate software distribution mechanisms, the actor can stealthily infiltrate high‑profile organizations across many geographies—including China, Taiwan, Korea, the United States, New Zealand, Russia, Israel, and beyond—collecting strategic intelligence while minimizing detection.
Enhanced Description
Key Capabilities
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
40
Techniques
62
Tools
7
Campaigns
55
IOCs
0
Observed Data
9
Tactics