DaemonicLogistics is a Windows malware component used by the China-aligned espionage group PlushDaemon as part of an adversary-in-the-middle software-update hijacking chain. It is delivered after the EdgeStepper network implant redirects legitimate update traffic to attacker-controlled infrastructure and after the first-stage downloader LittleDaemon is executed on the victim. Multiple sources in the content describe DaemonicLogistics as position-independent code that is downloaded by LittleDaemon, decrypted, and executed in memory. Its primary role is to download, deploy, and execute the group’s signature backdoor, SlowStepper, on Windows systems. The malware communicates over HTTP and, in reported cases, interprets HTTP status codes from the hijacked server as commands to control retrieval and installation of SlowStepper. Reported tradecraft includes in-memory execution, masquerading, and storage under directories named after legitimate software such as Tencent. One analyzed sample linked to DaemonicLogistics used a PDB path highly similar to known PlushDaemon tooling and a fake GIF artifact beginning with GIF89a\x10\x10; it read a path from the Apache_Fpath environment variable, XOR-decrypted payload data from the fake GIF, resolved ntdll APIs via obfuscated strings and LdrGetProcedureAddress, and used a custom in-memory PE loader with WriteProcessMemory and CreateThread for in-process memory injection. The broader campaign targeted victims in China, Hong Kong, Taiwan, Cambodia, New Zealand, South Korea, and the United States, including universities, manufacturing, automotive, and electronics-related entities. High-confidence indicators mentioned in the content include the PDB path D:\project\vs\zx\NSP64\x64\Release\MemloadX64.pdb, the Apache_Fpath environment variable, the fake GIF header GIF89a\x10\x10, and sample SHA256 993ba9ae2cacf8e6258c20c9cc7cc2fac1a7f0c518b298c19db696d5b691fbe7 for a DaemonicLogistics-linked loader sample.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the magic header used and the PDB path, which links it to DaemonicLogistics ... The implant implements a specific mechanism for loading an external piece of code ... In-Process Memory Injection ... This is essentially a custom Windows executable loader.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
LittleDaemon establishes communication with the attacker's hijacking node and fetches a second malware dropper named DaemonicLogistics, which is decrypted and executed in memory. In the next stage of the attack, the hackers use DaemonicLogistics to retrieve their signature backdoor, SlowStepper.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A low-detection Windows backdoor/loader DLL that masquerades as a Microsoft binary, resolves ntdll APIs dynamically to evade userland hooks, reads an encrypted fake GIF via the Apache_Fpath environment variable, decrypts an embedded payload, and performs in-process memory injection using a custom PE loader to execute the payload.
Downloader used to deploy the SlowStepper backdoor onto Windows systems.
DaemonicLogistics is a loader that interprets HTTP status codes from attacker infrastructure as commands to download and install the SlowStepper backdoor.
DaemonicLogistics is a downloader executed in memory by LittleDaemon. It communicates with attacker infrastructure to receive commands and download the SlowStepper backdoor or other payloads. It can check for security software and masquerade its payloads as legitimate files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.