Learn languages naturally with fresh, real content!

Popular Topics
Explore By Region
A China-linked group uses EdgeStepper to hijack router DNS queries, redirecting software updates to install backdoors since 2018.
A China-aligned hacking group, PlushDaemon, is using a newly discovered network implant called EdgeStepper to conduct adversary-in-the-middle attacks by hijacking DNS queries on compromised routers.
The tactic redirects legitimate software update traffic to malicious servers, enabling the deployment of backdoors like SlowStepper via downloaders such as LittleDaemon.
The group has targeted organizations in the U.S., Taiwan, South Korea, Cambodia, and elsewhere since at least 2018, exploiting unpatched vulnerabilities and weak credentials.
Recent attacks include supply-chain compromises of software and VPN providers, highlighting ongoing risks from network and update infrastructure manipulation.
Un grupo vinculado a China utiliza EdgeStepper para secuestrar las consultas DNS de los routers, redirigiendo las actualizaciones de software para instalar puertas traseras desde 2018.