Computer Security News

China Hackers Compromised VPN Service Provider in Supply-Chain Attack

A sophisticated supply-chain attack targeting a South Korean VPN provider. The attack has been attributed to a previously undisclosed China-aligned Advanced Persistent Threat (APT) group, now named PlushDaemon.

The operation, discovered in May 2024, involved the compromise of IPany, a legitimate VPN software developed by a South Korean company.

PlushDaemon replaced the official installer with a malicious version that deployed both the legitimate software and a custom backdoor called SlowStepper.

Malicious Page Installer

SlowStepper is a feature-rich implant with an extensive toolkit comprising over 30 components. This backdoor, programmed in C++, Python, and Go, showcases the group’s advanced capabilities and resources.

Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar

Malicious PlushDaemon Installer

ESET researchers believe PlushDaemon has been active since at least 2019, conducting espionage operations against targets in China, Taiwan, Hong Kong, South Korea, the United States, and New Zealand.

The group’s primary method of initial access involves hijacking legitimate updates of Chinese applications and redirecting traffic to attacker-controlled servers.

The compromised VPN installer was available for download from IPany’s official website as a ZIP archive. ESET found no evidence of targeted distribution, suggesting that any IPany VPN user could have been a potential victim.

Execution Flow

Upon discovery, ESET promptly notified the VPN software developer, who subsequently removed the malicious installer from their website.

ESET telemetry revealed that several users attempted to install the trojanized software within the networks of a semiconductor company and an unidentified software development firm in South Korea.

The oldest recorded cases in ESET’s telemetry date back to November 2023 for a victim in Japan and December 2023 for a victim in China.

This supply-chain attack marks a significant escalation in PlushDaemon’s tactics, demonstrating their ability to compromise not just Chinese applications but also South Korean software providers.

The group’s focus on VPN services is particularly concerning, as these tools are often used to secure sensitive communications and data transfers.

The discovery of PlushDaemon and its activities highlights the ongoing threat posed by state-sponsored cyber espionage campaigns. It underscores the importance of robust security measures throughout the software supply chain, as well as the need for constant vigilance against evolving cyber threats.

As tensions in the cybersecurity landscape continue to rise, this incident serves as a stark reminder of the sophisticated tactics employed by nation-state actors. Organizations and individuals alike must remain alert to the potential risks associated with even seemingly trustworthy software sources.

ESET’s research into PlushDaemon and the SlowStepper backdoor provides valuable insights for the cybersecurity community.

It enables better detection and prevention strategies against similar attacks in the future while also shedding light on the evolving tactics of China-aligned APT groups.

As investigations continue, cybersecurity experts urge users of IPany VPN and similar services to verify the integrity of their software installations and remain vigilant for any signs of compromise.

Here’s a table summarizing the Indicators of Compromise (IoCs) for the PlushDaemon supply-chain attack:

SHA-1FilenameDetectionDescription
A8AE42884A8EDFA17E9D67AE5BEBE7D196C3A7BFAutoMsg.dllWin32/ShellcodeRunner.GZInitial loader DLL
2DB60F0ADEF14F4AB3573F8309E6FB135F67ED7Dlregdll.dllWin32/Agent.AGUULoader DLL for the SlowStepper backdoor
846C025F696DA1F6808B9101757C005109F3CF3DOldLJM.dllWin32/Agent.AGXLInstaller DLL, extracted from EncMgr.pkg and executed in memory
AD4F0428FC9290791D550EEDDF171AFF046C4C2Csvcghost.exeWin32/Agent.AGUUProcess monitor component that launches PerfWatson.exe or RuntimeSvc.exe to side-load lregdll.dll
401571851A7CF71783A4CB902DB81084F0A97F85main.dllWin32/Agent.AEIJDecrypted SlowStepper backdoor component
068FD2D209C0BBB0C6FC14E88D63F92441163233IPanyVPNsetup.exeWin32/ShellcodeRunner.GZMalicious IPany installer containing SlowStepper implant and legitimate IPany VPN software

These IoCs provide crucial information for identifying and mitigating the PlushDaemon threat. Security teams should use these file hashes and names to scan their systems and networks for potential compromises.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago