URL has been copied successfully!
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates

The threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed EdgeStepper to facilitate adversary-in-the-middle (AitM) attacks.EdgeStepper “redirects all DNS queries to an external, malicious hijacking node, effectively rerouting the traffic from legitimate infrastructure used for software updates to attacker-controlled infrastructure

First seen on thehackernews.com

Jump to article: thehackernews.com/2025/11/edgestepper-implant-reroutes-dns.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link