Last seven days
- First activity
- Aug 8, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
LittleDaemon is a custom Windows downloader used by the China-aligned espionage group PlushDaemon as the first stage in a hijacked software-update infection chain.
Profile source: Mallory opens in a new tabLittleDaemon
LittleDaemon is a custom Windows downloader used by the China-aligned espionage group PlushDaemon as the first stage in a hijacked software-update infection chain. ESET reporting states it is delivered through adversary-in-the-middle attacks enabled by the group’s EdgeStepper network implant, which redirects DNS queries for legitimate software update domains to attacker-controlled infrastructure. The malware has been observed in both DLL and executable 32-bit PE forms and is commonly disguised as a DLL, including as popup_4.2.0.2246.dll. Its primary function is to communicate with the attacker-controlled hijacking node and, if the group’s SlowStepper backdoor is not already present or running on the victim system, fetch the next-stage downloader DaemonicLogistics, which then leads to deployment of SlowStepper on Windows machines. The campaign has included hijacking updates for popular Chinese software such as Sogou Pinyin. LittleDaemon itself does not establish persistence. Reported targeting associated with PlushDaemon includes organizations and individuals in China, Hong Kong, Taiwan, Cambodia, New Zealand, South Korea, and the United States, including universities and manufacturing-related entities. High-confidence indicators directly mentioned in the content include the masqueraded filename popup_4.2.0.2246.dll and its role in the EdgeStepper -> LittleDaemon -> DaemonicLogistics -> SlowStepper infection chain.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
“…PlushDaemon that leveraged the same technique to distribute a custom downloader called LittleDaemon.”
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.