s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.little_daemon

📛 Threat Title

Malware family: LittleDaemon

Category: LittleDaemon First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.little_daemon`. Printable name: LittleDaemon.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:botcrawl.com

    PlushDaemon redirects software update traffic through malicious DNS nodes to deliver custom malware including EdgeStepper, LittleDaemon , and SlowStepper.

  • web:cybersecuritymarket.com

    Once that traffic rerouting succeeds, PlushDaemon begins dropping tools with almost theatrical naming flair — LittleDaemon , DaemonicLogistics, and eventually the real objective: SlowStepper, a modular espionage backdoor with dozens of components.

  • web:gbhackers.com

    When legitimate software requests an update through EdgeStepper's compromised network, the hijacking node serves LittleDaemon , a 32-bit PE executable that functions as the first-stage payload. LittleDaemon checks whether the SlowStepper backdoor already exists on the system and, if absent, downloads DaemonicLogistics a position-independent code executed directly in memory without touching disk.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to ESET Research, LittleDaemon is the first stage deployed on the victim's machine through hijacked updates. It was observed in both DLL and executable versions, both of them 32-bit PEs. The main purpose of LittleDaemon is to communicate with the hijacking node to obtain the downloader that we call DaemonicLogistics.

  • web:securitricks.com

    PlushDaemon's adversary-in-the-middle technique involves compromising network devices, deploying EdgeStepper, and using it to redirect DNS queries for software updates to malicious nodes. This allows them to serve malicious updates containing the LittleDaemon downloader, which then deploys the SlowStepper implant.

  • web:thehackernews.com

    PlushDaemon hijacks software updates using EdgeStepper to redirect DNS traffic and deploy SlowStepper malware .

  • web:www.bleepingcomputer.com

    LittleDaemon establishes communication with the attacker's hijacking node and fetches a second malware dropper named DaemonicLogistics, which is decrypted and executed in memory. In the next stage ...

  • web:www.eset.com

    ESET researchers discovered that China-aligned threat group PlushDaemon performs adversary-in-the-middle attacks using a previously undocumented network implant.

  • web:www.techradar.com

    China-aligned hacking group PlushDaemon has been spotted by ESET targeting routers and other network devices with malware to launch supply chain attacks.

  • web:www.welivesecurity.com

    ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.