Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareUsed by 1 actor

LittleDaemon

LittleDaemon is a custom Windows downloader used by the China-aligned espionage group PlushDaemon as the first stage in a hijacked software-update infection chain. ESET reporting states it is delivered through adversary-in-the-middle attacks enabled by the group’s EdgeStepper network implant, which redirects DNS queries for legitimate software update domains to attacker-controlled infrastructure. The malware has been observed in both DLL and executable 32-bit PE forms and is commonly disguised as a DLL, including as popup_4.2.0.2246.dll. Its primary function is to communicate with the attacker-controlled hijacking node and, if the group’s SlowStepper backdoor is not already present or running on the victim system, fetch the next-stage downloader DaemonicLogistics, which then leads to deployment of SlowStepper on Windows machines. The campaign has included hijacking updates for popular Chinese software such as Sogou Pinyin. LittleDaemon itself does not establish persistence. Reported targeting associated with PlushDaemon includes organizations and individuals in China, Hong Kong, Taiwan, Cambodia, New Zealand, South Korea, and the United States, including universities and manufacturing-related entities. High-confidence indicators directly mentioned in the content include the masqueraded filename popup_4.2.0.2246.dll and its role in the EdgeStepper -> LittleDaemon -> DaemonicLogistics -> SlowStepper infection chain.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
PlushDaemon

“…PlushDaemon that leveraged the same technique to distribute a custom downloader called LittleDaemon.”

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1195Supply Chain CompromiseEvidence1

Telemetry data from cybersecurity firm ESET indicates that since 2019, the threat actor has relied on malicious updates to breach target networks.

T1195.002Compromise Software Supply ChainEvidence1

"...hijacking the software update mechanism associated with Sogou Pinyin..."; "...hijack the software update process for Tencent QQ... to serve a trojanized version"

Execution

1 technique
T1574.001DLLEvidence2

When a victim tries to update their software, they receive the first-stage malware downloader for Windows called LittleDaemon, which is disguised as a DLL file named ‘popup_4.2.0.2246.dll.’

Stealth

3 techniques
T1036MasqueradingEvidence1

The payload chain typically begins with LittleDaemon, a downloader posing as a DLL...

T1140Deobfuscate/Decode Files or InformationEvidence1

LittleDaemon establishes communication with the attacker's hijacking node and fetches a second malware dropper named DaemonicLogistics, which is decrypted and executed in memory.

T1574.001DLLEvidence2

When a victim tries to update their software, they receive the first-stage malware downloader for Windows called LittleDaemon, which is disguised as a DLL file named ‘popup_4.2.0.2246.dll.’

Credential Access

1 technique
T1557Adversary-in-the-MiddleEvidence2

A China-linked threat actor tracked as 'PlushDaemon' is hijacking software update traffic using a new implant called EdgeStepper in cyberespionage operations.

Collection

1 technique
T1557Adversary-in-the-MiddleEvidence2

A China-linked threat actor tracked as 'PlushDaemon' is hijacking software update traffic using a new implant called EdgeStepper in cyberespionage operations.

Command and Control

1 technique
T1105Ingress Tool TransferEvidence3

A first-stage deployed through hijacked updates, LittleDaemon is designed to communicate with the attacker node to fetch a downloader referred to as DaemonicLogistics if SlowStepper is not running on the infected system. The main purpose of DaemonicLogistics is to download the SlowStepper backdoor from the server and execute it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.