Skip to content

LittleDaemon

LittleDaemon is a custom Windows downloader used by the China-aligned espionage group PlushDaemon as the first stage in a hijacked software-update infection chain.

Profile source: Mallory opens in a new tab

LittleDaemon

Family profile

LittleDaemon is a custom Windows downloader used by the China-aligned espionage group PlushDaemon as the first stage in a hijacked software-update infection chain. ESET reporting states it is delivered through adversary-in-the-middle attacks enabled by the group’s EdgeStepper network implant, which redirects DNS queries for legitimate software update domains to attacker-controlled infrastructure. The malware has been observed in both DLL and executable 32-bit PE forms and is commonly disguised as a DLL, including as popup_4.2.0.2246.dll. Its primary function is to communicate with the attacker-controlled hijacking node and, if the group’s SlowStepper backdoor is not already present or running on the victim system, fetch the next-stage downloader DaemonicLogistics, which then leads to deployment of SlowStepper on Windows machines. The campaign has included hijacking updates for popular Chinese software such as Sogou Pinyin. LittleDaemon itself does not establish persistence. Reported targeting associated with PlushDaemon includes organizations and individuals in China, Hong Kong, Taiwan, Cambodia, New Zealand, South Korea, and the United States, including universities and manufacturing-related entities. High-confidence indicators directly mentioned in the content include the masqueraded filename popup_4.2.0.2246.dll and its role in the EdgeStepper -> LittleDaemon -> DaemonicLogistics -> SlowStepper infection chain.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 8, 2026
Last activity
Aug 8, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • CN1

Leading providers

  • CHINANET BACKBONE1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
PlushDaemon

“…PlushDaemon that leveraged the same technique to distribute a custom downloader called LittleDaemon.”

MITRE ATT&CK

LittleDaemon in ATT&CK

12 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.