← Back to Feed

PlushDaemon compromises network devices for adversary-in-the-middle attacks

November 19, 2025 · WeLiveSecurity · Severity: MEDIUM

ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks

Key Takeaways

  • ESET discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks.
  • The PlushDaemon network implant compromises networking devices in order to intercept traffic for adversary-in-the-middle attacks.
  • Network operators should monitor for unauthorized device modifications and review ESET's PlushDaemon research for indicators.
☕ Buy a Coffee