Skip to content
PlushDaemon Hackers Use EdgeStepper to Hijack Software Updates

PlushDaemon Hackers Use EdgeStepper to Hijack Software Updates

First seen 2 Dec 2025, 18:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The China-linked threat actor PlushDaemon has been exploiting a new implant named EdgeStepper to hijack software update traffic. This cyberespionage operation has targeted various organizations across the United States, China, Taiwan, Hong Kong, South Korea, and New Zealand since at least 2018, redirecting DNS queries to malicious servers to deliver harmful payloads.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (9)

Following this threat?

Track PlushDaemon, DaemonicLogistics and Alibaba Cloud LLC in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed