SlowStepper Backdoor Malware
Summary
In 2023, a previously undocumented China-aligned Advanced Persistent Threat (APT) group, PlushDaemon, emerged on the cybersecurity radar following a sophisticated supply chain attack on a South Korean VPN provider. Despite this, it retains significant capabilities, enabling comprehensive surveillance and data collection through tools hosted on GitCode, a Chinese code repository. Unique features include the ability to launch a custom shell for executing remote payloads and Python modules for specific tasks. The groups operations since 2019 highlight a clear focus on creating sophisticated tools, positioning it as a significant threat in the cybersecurity landscape. By targeting trusted software distribution channels, the group has demonstrated its ability to infiltrate networks and execute complex espionage campaigns.