DaemonicLogistics is a malware toolset associated with the Chinese espionage cluster PlushDaemon. It has been linked through distinctive development artifacts and loader behavior to espionage activity attributed to a China-aligned operator. The tooling includes a low-detection DLL backdoor and loader components designed for stealthy in-memory execution. Observed DaemonicLogistics samples masquerade as legitimate software while avoiding straightforward static detection. They resolve native APIs from ntdll through obfuscated strings and use LdrGetProcedureAddress rather than higher-level Win32 API resolution, a technique consistent with defense evasion and reduced exposure to userland security hooks. The malware reads an external encrypted payload, decrypts it, and executes it through a custom in-memory PE loader. Execution involves writing multiple components into memory and launching them via a new thread, reflecting process injection and post-exploitation tradecraft. The tooling has been associated with PlushDaemon through shared development-path conventions and a distinctive fake-GIF payload format. PlushDaemon has been documented as a Chinese espionage actor, and DaemonicLogistics appears to function as part of that broader intrusion ecosystem. Reporting on the cluster has also linked it to compromises of network devices for adversary-in-the-middle operations, indicating a wider espionage capability set beyond endpoint malware alone.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.