National Cyber Warfare Foundation (NCWF)

EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates


0 user ratings
2025-11-19 10:30:24
milo
Blue Team (CND) , Attacks
The threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed EdgeStepper to facilitate adversary-in-the-middle (AitM) attacks.
EdgeStepper "redirects all DNS queries to an external, malicious hijacking node, effectively rerouting the traffic from legitimate infrastructure used for software updates to attacker-controlled infrastructure



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/11/edgestepper-implant-reroutes-dns.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Attacks



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.