📈 Get daily crypto insights that make you smarter about your money

PlushDaemon APT Compromises South Korean VPN Provider in Sophisticated Supply Chain Attack

A newly discovered China-aligned advanced persistent threat group, dubbed PlushDaemon, has been linked to a supply chain attack against a South Korean VPN service provider, highlighting the escalating risks facing the cryptocurrency and broader technology ecosystem. Uncovered by ESET researchers on January 22, 2025, the operation reveals how state-sponsored threat actors continue to exploit trusted software distribution channels to deploy sophisticated surveillance tools.

The Exploit Mechanics

The attack centered on IPany, a legitimate VPN service developed by a South Korean company and distributed through the website ipany.kr. PlushDaemon operators replaced the legitimate VPN installer with a trojanized NSIS installer packaged inside a ZIP archive called IPanyVPNsetup.zip. When users downloaded and executed the installer, it deployed both the legitimate VPN software and a feature-rich backdoor that ESET has named SlowStepper.

The SlowStepper implant is remarkably comprehensive, featuring a toolkit composed of more than 30 modules programmed in C++, Python, and Go. This multi-language architecture suggests a well-resourced development team with diverse capabilities. The backdoor establishes persistence on compromised systems and provides operators with extensive surveillance and data exfiltration capabilities.

Affected Systems

Through ESET telemetry, researchers identified several victims who installed the trojanized software, including systems within a semiconductor company and an unidentified software development firm in South Korea. The oldest detected cases date back to November 2023 in Japan and December 2023 in China, indicating the campaign has been active for well over a year before discovery.

PlushDaemon has been active since at least 2019, conducting espionage operations against individuals and entities in China, Taiwan, Hong Kong, South Korea, the United States, and New Zealand. The group primarily gains initial access by hijacking legitimate software updates, redirecting traffic to attacker-controlled servers. They have also been observed exploiting vulnerabilities in legitimate web servers to establish a foothold.

The Mitigation Strategy

ESET contacted the VPN software developer directly after discovering the compromise, and the malicious installer was promptly removed from the IPany website. Organizations can protect themselves by verifying software integrity through cryptographic hash checks before installation, implementing application whitelisting policies, and maintaining robust endpoint detection and response solutions that can identify suspicious installer behavior.

For cryptocurrency users and exchanges, this incident underscores the importance of downloading wallet software and security tools exclusively from verified official sources. Supply chain attacks represent one of the most dangerous threat vectors because they exploit inherent trust in established software vendors.

Lessons Learned

The PlushDaemon campaign demonstrates that supply chain attacks continue to evolve in sophistication. The use of a legitimate VPN installer as a delivery mechanism is particularly concerning for privacy-conscious users who actively seek out VPN solutions. The multi-year operational timeline suggests patient, well-funded threat actors with specific intelligence collection objectives.

User Action Required

Anyone who downloaded IPany VPN software between late 2023 and May 2024 should conduct a full system audit and check for indicators of compromise associated with SlowStepper. Organizations should review their software supply chain security policies, ensure multi-factor authentication is enabled on all critical accounts, and consider implementing behavioral analytics to detect anomalous processes running alongside legitimate applications. As Bitcoin trades near $103,653 and the broader crypto market continues to attract institutional capital, the threat landscape targeting digital asset infrastructure grows proportionally more complex.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with qualified security professionals.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

27 thoughts on “PlushDaemon APT Compromises South Korean VPN Provider in Sophisticated Supply Chain Attack”

  1. supply_chain_rat_

    30+ modules in SlowStepper is absurd for a VPN backdoor. PlushDaemon spent more dev time on surveillance tooling than most L2s spend on their entire stack

    1. supply_chain_rat_ the C++ Python Go triple stack is classic APT toolbox design. each language handles a different exfil channel so killing one module doesnt stop the others

  2. IPany is a real VPN used by crypto exchanges in Korea for internal routing. if the backdoor captured API keys the fallout could be way worse than what ESET published

      1. codebase_auditor_

        30 modules across three languages means this team has dedicated frontend, backend, and infra engineers. APT groups have better engineering practices than most DeFi protocols

        1. supply_chain_rat_

          talking about checksums while the attacker replaced the actual installer on the official site is wild. integrity monitoring should detect own infrastructure changes

      2. C++, Python, and Go in one implant means this team has serious talent. China aligned APT with that kind of multi-language capability is concerning for crypto infrastructure

      3. malware_hunter

        30 modules across three languages means a dedicated team with QA and testing pipelines. this isnt a side project, its a full intelligence operation

        1. 30 modules in cpp python and go is basically a full dev team. this isnt some ransomware crew, its government budget

        2. SlowStepper having 30+ modules across three languages is wild. most ransomware crews barely manage clean C++ and these operators are running a full dev shop

      1. you protect against supply chain attacks by verifying signatures independently and not trusting the download page. ESET caught this one, the next one might go unnoticed

        1. signature verification only works if the signing key itself isnt compromised. if they replaced the installer they could have replaced the signature too

        2. SupplyChainExpert

          Trojanized NSIS installer from the official site is why reproducible builds matter. Your checksums don’t help when the source itself is compromised and nobody notices for weeks.

  3. sig_verify_fail

    reproducible builds have been the answer for years and adoption is still basically zero. everyone just trusts the download page

  4. SlowStepper communicating with 30+ C2 modules means the operators had real time surveillance capabilities. this isnt financial theft, its intelligence gathering

    1. Anneli M. 30 modules across 3 languages is basically a full engineering org. DPRK dev shops have better QA than most early stage crypto startups honestly

  5. the official distribution channel was compromised for weeks and nobody at IPany noticed their own download page was serving malware. basic integrity monitoring would have caught this

  6. slowstepper is a fitting name. 30 modules patiently gathering intel over weeks while nobody notices. state-level patience vs standard crypto OpSec

  7. checksum_grind_

    ESET found it because someone was comparing checksums across builds. one researcher doing what the entire IPany team should have been doing for weeks

  8. nobody verifies signatures though. like actually nobody. even most devs just download and run. reproducible builds would solve this but adoption is near zero

  9. IPany replaced the installer on their own site and nobody noticed for weeks probably. supply chain attacks work because nobody checks checksums until its too late

    1. ipany had the trojanized installer on their own download page. your checksums dont matter when the source itself is compromised

  10. SecurityResearcher

    30+ modules across C++, Python, and Go in one backdoor is basically a full dev team. This isn’t ransomware, it’s a nation-state level intelligence operation on crypto infrastructure.

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,942.00-1.9%ETH$1,872.49-2.7%SOL$76.25-1.4%BNB$599.05-1.5%XRP$1.02-2.5%ADA$0.1921-3.0%DOGE$0.0697-1.2%DOT$0.80910.0%AVAX$6.43-2.1%LINK$8.28-0.6%UNI$3.95-3.3%ATOM$1.40+0.9%LTC$45.05-2.2%ARB$0.0796-1.0%NEAR$1.60-2.2%FIL$0.6997-1.8%SUI$0.6870-2.1%BTC$63,942.00-1.9%ETH$1,872.49-2.7%SOL$76.25-1.4%BNB$599.05-1.5%XRP$1.02-2.5%ADA$0.1921-3.0%DOGE$0.0697-1.2%DOT$0.80910.0%AVAX$6.43-2.1%LINK$8.28-0.6%UNI$3.95-3.3%ATOM$1.40+0.9%LTC$45.05-2.2%ARB$0.0796-1.0%NEAR$1.60-2.2%FIL$0.6997-1.8%SUI$0.6870-2.1%
Scroll to Top