EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates



The threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed EdgeStepper to facilitate adversary-in-the-middle (AitM) attacks.
EdgeStepper "redirects all DNS queries to an external, malicious hijacking node, effectively rerouting the traffic from legitimate infrastructure used for software updates to attacker-controlled infrastructure


Fonte: Leia a matéria original

No comments:

Post a Comment

A.I. Toy Bear Speaks of Sex, Knives and Pills, Consumer Group Warns

The chatter left startled adults unsure whether they heard correctly. Testers warned that interactive toys like this one could allow childre...