🇨🇳PlushDaemon
🇨🇳 PlushDaemon is a tracked threat actor in the Clankerusecase corpus. Attributed to CN. Primary motivation: State. We map 14 detection use cases to this actor across 56 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2025-11-19 to 2025-12-18.
crit 2
14Use cases
2Articles
56Techniques
4IOCs
Known aliases
PlushDaemon
Top techniques
All other tracked techniques
T1016 · System Network Configuration DiscoveryT1021.002 · SMB/Windows Admin SharesT1027.009 · Embedded PayloadsT1027.015 · CompressionT1036.008 · Masquerade File TypeT1053.005 · Scheduled TaskT1055 · Process InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1074.001 · Local Data StagingT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1098.001 · Additional Cloud CredentialsT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1106 · Native APIT1125 · Video CaptureT1190 · Exploit Public-Facing ApplicationT1195.002 · Compromise Software Supply ChainT1204.002 · Malicious FileT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1480 · Execution GuardrailsT1518.001 · Security Software DiscoveryT1528 · Steal Application Access TokenT1555.003 · Credentials from Web BrowsersT1560 · Archive Collected DataT1562.001 · T1562.001T1564.003 · Hidden WindowT1567.002 · Exfiltration to Cloud StorageT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1573 · Encrypted ChannelT1573.001 · Symmetric CryptographyT1573.002 · Asymmetric CryptographyT1574.014 · AppDomainManagerT1583.001 · DomainsT1583.002 · DNS ServerT1583.004 · ServerT1585.003 · Cloud AccountsT1588.001 · MalwareT1608.001 · Upload MalwareT1620 · Reflective Code LoadingT1622 · Debugger EvasionT1659 · Content InjectionT1665 · Hide Infrastructure
Detection use cases (14)
PlushDaemon SlowStepper C2 discovery via non-browser DNS to public resolvers PlushDaemon EdgeStepper update-hijack: signed updater fetching payload from raw-IP host NosyDoor AppDomainManager hijack: UevAppMonitor.exe executing from non-standard path NosyDoor persistence: scheduled task 'OneDrive Reporting Task-S-1-5-21-' under Microsoft folder NosyDoor dropper file artefacts in C:\Windows\Microsoft.NET\Framework Beaconing — periodic outbound to small set of destinations Remote service execution — PsExec / SMB lateral movement OAuth consent / suspicious app grant Scheduled task created with suspicious image / encoded args PowerShell encoded / obfuscated command RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Article-specific behavioural hunt — LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Ja PlushDaemon EdgeStepper hijacking infrastructure (wcsset.com / 47.242.198.250 / 8.212.132.120) contact LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2.Threat-intel articles (2)
Tracked indicators
Domains (2)
ds20221202.dsc.wcsset.co test.dsc.wcsset.comIP addresses (2)
119.136.153.0 47.242.198.250