PlushDaemon global espionage campaign
Campaign
Summary
Hide ▲
Show ▼
PlushDaemon is running a long-lived global espionage campaign that targets organizations across multiple countries, increasing the risk of cross-border compromise and repeated follow-on intrusions. The operation uses hijacked software updates and a malicious DNS node to support adversary-in-the-middle access and payload delivery. Researchers also linked the activity to a May 2024 supply-chain attack against IPany.
Related Happenings
OceanLotus SPECTRALVIPER campaigns targeting Vietnam
Campaign
H score33
First: 11.06.2026 12:45
Last: 11.06.2026 12:45
Sources 1
About this happening:
OceanLotus expanded its Vietnam-focused espionage operations with two attributed campaigns using SPECTRALVIPER, broadening risk to a Vietnamese infrastructure and tr...
OceanLotus SPECTRALVIPER campaigns targeting Vietnam
CampaignAbout this happening: OceanLotus expanded its Vietnam-focused espionage operations with two attributed campaigns using SPECTRALVIPER, broadening risk to a Vietnamese infrastructure and tr...
Evasive Panda DNS poisoning MgBot espionage campaign
Campaign
H score33
First: 26.12.2025 16:44
Last: 26.12.2025 16:44
Sources 1
About this happening:
Evasive Panda ran a highly targeted cyber espionage campaign that used DNS poisoning to deliver MgBot to victims in Türkiye, China, and India. The operation wa...
Evasive Panda DNS poisoning MgBot espionage campaign
CampaignAbout this happening: Evasive Panda ran a highly targeted cyber espionage campaign that used DNS poisoning to deliver MgBot to victims in Türkiye, China, and India. The operation wa...
LongNosedGoblin cyber-espionage campaign targeting government entities in Southeast Asia and Japan
Campaign
H score33
First: 18.12.2025 19:34
Last: 18.12.2025 19:34
Sources 1
About this happening:
A LongNosedGoblin campaign is targeting governmental entities in Southeast Asia and Japan, creating a sustained risk of cyber espionage and file exfiltration insid...
LongNosedGoblin cyber-espionage campaign targeting government entities in Southeast Asia and Japan
CampaignAbout this happening: A LongNosedGoblin campaign is targeting governmental entities in Southeast Asia and Japan, creating a sustained risk of cyber espionage and file exfiltration insid...
UDPGangster backdoor deployed by MuddyWater
Malware Activity
H score22
First: 08.12.2025 08:46
Last: 08.12.2025 08:46
Sources 1
About this happening:
The MuddyWater group has deployed UDPGangster, a new backdoor that uses UDP C2 to control compromised systems and expand post-compromise access. The malware can exec...
UDPGangster backdoor deployed by MuddyWater
Malware ActivityAbout this happening: The MuddyWater group has deployed UDPGangster, a new backdoor that uses UDP C2 to control compromised systems and expand post-compromise access. The malware can exec...
MuddyWater phishing campaign targeting Israeli entities with MuddyViper
Campaign
H score33
First: 02.12.2025 15:37
Last: 02.12.2025 15:37
Sources 1
About this happening:
A MuddyWater phishing campaign is targeting Israeli academia, government, industry, transport, and utilities, and the operation matters because it is delivering the Mudd...
MuddyWater phishing campaign targeting Israeli entities with MuddyViper
CampaignAbout this happening: A MuddyWater phishing campaign is targeting Israeli academia, government, industry, transport, and utilities, and the operation matters because it is delivering the Mudd...
Timeline
-
19.11.2025 14:00 2 articles · 7mo ago
PlushDaemon deploys undocumented AitM implant
Initial DisclosurePlushDaemon’s espionage activity is publicly described as using an undocumented adversary-in-the-middle implant, bioset / dns_cheat_v2, that forwards DNS traffic from targeted networks to a malicious DNS node, enabling software-update hijacking and delivery of the LittleDaemon and DaemonLogistics backdoor toolkit. Researchers also linked the group to a May 2024 supply-chain attack on IPany and described broader targeting of organizations in Cambodia, South Korea, New Zealand, the US, Taiwan, Hong Kong, and China since at least 2018.
Show sources
- PlushDaemon Hackers Unleash New Malware in China-Aligned Spy Campaigns — www.infosecurity-magazine.com — 19.11.2025 14:00
- PlushDaemon Hackers Unleash New Malware in China-Aligned Spy Campaigns — www.infosecurity-magazine.com — 19.11.2025 14:00