Skip to content
PlushDaemon Hackers Exploit EdgeStepper Tool for Software Update Hijacking

PlushDaemon Hackers Exploit EdgeStepper Tool for Software Update Hijacking

First seen 19 Nov 2025, 16:15 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The Chinese hacking group PlushDaemon has been observed using a tool named EdgeStepper to hijack legitimate software updates, redirecting traffic to malicious servers. Active since at least 2018, PlushDaemon targets organizations globally, including the US, South Korea, and New Zealand, employing adversary-in-the-middle techniques to compromise network devices and conduct cyber espionage.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (9)

Following this threat?

Track PlushDaemon, DaemonicLogistics and Alibaba Cloud LLC in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed