MIT TRACE

MIT CTL Logo
Back to Main Dashboard

PlushDaemon compromises IPany installer in software supply-chain attack

ESET found that attackers replaced IPany's legitimate Windows VPN installer with a trojanized installer delivering the SlowStepper backdoor. Telemetry showed installations inside a South Korean semiconductor company and software-development company, with earlier infected victims in Japan and China; the malicious installer was removed after ESET notified the provider in May 2024.

73

Estimated severity

73 / 100

90

Source reliability

90 / 100

Approximate Date

22/01/2025

Targeted Company

IPANY

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

South Korea

KOR

Other Affected Countries

Japan

JPN

China

CHN

Target country

South Korea

Affected countries

South KoreaJapanChina

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT ServicesManufacturing

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalwareBackdoor

Attributed threat actors

PLUSHDAEMON

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.