Skip to content

Malware

LittleDaemon

According to ESET Research, LittleDaemon is the first stage deployed on the victim’s machine through hijacked updates.

LittleDaemon is a Linux malware family operated by PlushDaemon.

Background

ESET Research reports that LittleDaemon is the initial stage delivered to a victim's machine via hijacked updates. It has appeared as both a DLL and an executable, both 32-bit PEs. Its primary role is to contact the hijacking node and fetch the downloader ESET calls DaemonicLogistics, and it does not set up persistence.


Source: Malpedia (Fraunhofer FKIE).