Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareUsed by 1 actor

DaemonicLogistics

DaemonicLogistics is a Windows-stage downloader/dropper used by the China-aligned espionage group PlushDaemon as part of an adversary-in-the-middle software-update hijacking chain. It is delivered after the LittleDaemon downloader, which is pushed via EdgeStepper, a network implant placed on compromised routers and other edge devices that hijacks DNS responses for legitimate software update domains. DaemonicLogistics is described as position-independent code that is decrypted and executed in memory by LittleDaemon. Its primary purpose is to download, deploy, and execute PlushDaemon’s signature backdoor, SlowStepper, on victim Windows systems. Reporting states that it interprets HTTP status codes from the hijacked server as commands to control the download and installation of SlowStepper. One report also states that it checks for the presence of 360tray.exe (360 Total Security) before deploying SlowStepper, and that it may store files in directories named after legitimate software such as Tencent to masquerade as benign. The broader campaign has targeted organizations and individuals in China, Hong Kong, Taiwan, Cambodia, South Korea, New Zealand, and the United States, including universities and manufacturing-related entities, by abusing trusted update mechanisms such as Sogou Pinyin updates.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
PlushDaemon

"We provide an analysis of LittleDaemon and DaemonicLogistics, two downloaders that deploy the group’s signature SlowStepper backdoor on Windows machines."

via ctoatncsc substackctoatncsc.substack.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1195Supply Chain CompromiseEvidence1

Telemetry data from cybersecurity firm ESET indicates that since 2019, the threat actor has relied on malicious updates to breach target networks.

Stealth

1 technique
T1140Deobfuscate/Decode Files or InformationEvidence1

LittleDaemon establishes communication with the attacker's hijacking node and fetches a second malware dropper named DaemonicLogistics, which is decrypted and executed in memory.

Credential Access

1 technique
T1557Adversary-in-the-MiddleEvidence2

A China-linked threat actor tracked as 'PlushDaemon' is hijacking software update traffic using a new implant called EdgeStepper in cyberespionage operations.

Collection

1 technique
T1557Adversary-in-the-MiddleEvidence2

A China-linked threat actor tracked as 'PlushDaemon' is hijacking software update traffic using a new implant called EdgeStepper in cyberespionage operations.

Command and Control

1 technique
T1105Ingress Tool TransferEvidence3

LittleDaemon establishes communication with the attacker's hijacking node and fetches a second malware dropper named DaemonicLogistics, which is decrypted and executed in memory. In the next stage of the attack, the hackers use DaemonicLogistics to retrieve their signature backdoor, SlowStepper.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.