EdgeStepper Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
November 19, 2025
Last Seen
December 16, 2025

Related Threat Clusters

  • Remote Code Execution Flaw Discovered in Glob File Matching Library

    Researchers have identified a remote code execution vulnerability in the glob file pattern matching library, specifically within the command-line interface (CLI) tool's –c flag. This flaw affects users who utilize glob,…

    2 articles · Updated November 23, 2025
  • Remote Code Execution Flaw Found in Glob File Matching Library

    Researchers have identified a remote code execution vulnerability in the glob file pattern matching library's CLI tool. This flaw, which has existed for years, affects users who utilize the tool's –c flag to execute…

    2 articles · Updated November 23, 2025
  • PlushDaemon Hackers Exploit EdgeStepper Tool for Software Update Hijacking

    The Chinese hacking group PlushDaemon has been observed using a tool named EdgeStepper to hijack legitimate software updates, redirecting traffic to malicious servers. Active since at least 2018, PlushDaemon targets…

    9 articles · Updated November 19, 2025
  • Rise of AI-Driven Attacks and NFC Threats in Cybersecurity

    ESET Research reports a significant increase in AI-powered malware and NFC threats in late 2025. The MuddyWater group, aligned with Iran, has been targeting critical infrastructure in Israel and Egypt, while the…

    2 articles · Updated December 18, 2025
  • PlushDaemon Hackers Use EdgeStepper to Hijack Software Updates

    The China-linked threat actor PlushDaemon has been exploiting a new implant named EdgeStepper to hijack software update traffic. This cyberespionage operation has targeted various organizations across the United States,…

    9 articles · Updated November 20, 2025

Recent Intelligence Reports

  • ESET Threat Report: AI-driven attacks on the rise; NFC — Globenewswire · December 16, 2025
  • Weaponized file name flaw allows RCE through glob — Theregister · November 23, 2025
  • Weaponized file name flaw makes updating glob an urgent job — Theregister · November 23, 2025
  • New EdgeStepper implant leveraged in PlushDaemon supply chain compromise — Scworld · November 20, 2025
  • PlushDaemon Hackers in China Deploy EdgeStepper to Corrupt Software Updates and ... — Cyberpress · November 20, 2025
  • China‑linked PlushDaemon hijacks DNS via 'EdgeStepper' to weaponize software updates — Csoonline · November 20, 2025
  • China‑linked PlushDaemon hijacks DNS via ‘EdgeStepper’ to weaponize software updates — Csoonline · November 20, 2025
  • Chinese PlushDaemon Hackers use EdgeStepper Tool to Hijack Legitimate Updates and Redirect to Malicious Servers — Cybersecuritynews · November 19, 2025

CVSS v3.1 Breakdown