TF-MAL-elf.edgestepper
📛 Threat Title
Malware family: EdgeStepper
Description
ThreatFox malware family `elf.edgestepper`. Printable name: EdgeStepper.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.edgestepper
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.edgestepper
IOC database
- Type
- domain
- Value
elf.edgestepper- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.edgestepper
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.edgestepper
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:aviatrix.ai
The 2025 EdgeStepper DNS hijack by PlushDaemon exposed supply chain risks via adversary-in-the-middle attacks on software updates. Learn threat, impact, and defense.
-
web:botcrawl.com
PlushDaemon redirects software update traffic through malicious DNS nodes to deliver custom malware including EdgeStepper , LittleDaemon, and SlowStepper.
-
web:cybernoz.com
The threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed EdgeStepper to facilitate adversary-in-the-middle (AitM) attacks. EdgeStepper "redirects all DNS queries to an external, malicious hijacking node, effectively rerouting the traffic from legitimate infrastructure used for software updates to attacker-controlled ...
-
web:cybersecuritynews.com
PlushDaemon uses its EdgeStepper tool to hijack software updates and inject malware , targeting users across the US, Asia, and New Zealand.
-
web:imtr.net
The threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed EdgeStepper to facilitate adversary-in-the-middle (AitM) attacks. EdgeStepper "redirects all DNS queries to an external, malicious hijacking node, effectively rerouting the traffic from legitimate infrastructure used for software updates to attacker-controlled ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to ESET Research, EdgeStepper is an adversary-in-the-middle tool, which forwards DNS traffic from machines in a targeted network to a malicious DNS node. This allows the attackers to redirect the traffic from software updates to a hijacking node that serves instructions to the legitimate software to download a malicious update.
-
web:thehackernews.com
PlushDaemon hijacks software updates using EdgeStepper to redirect DNS traffic and deploy SlowStepper malware .
-
web:www.bleepingcomputer.com
A China-linked threat actor tracked as 'PlushDaemon' is hijacking software update traffic using a new implant called EdgeStepper in cyberespionage operations. Since 2018, PlushDaemon hackers have ...
-
web:www.cistck.com
by admin | Nov 19, 2025 The threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed EdgeStepper to facilitate adversary-in-the-middle (AitM) attacks. EdgeStepper "redirects all DNS queries to an external, malicious hijacking node, effectively rerouting the traffic from legitimate infrastructure used for software updates to ...
-
web:www.learnexplore.org
November 19, 2025 Uncategorized 0 The threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed EdgeStepper to facilitate adversary-in-the-middle (AitM) attacks. EdgeStepper "redirects all DNS queries to an external, malicious hijacking node, effectively rerouting the traffic from legitimate infrastructure used for software ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.