Kaspersky says Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates
Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates …
Ars TechnicaDan Goodin
Context & Ripple Effects
This sits in a recurring supply-chain security pattern in the related coverage: compromised update mechanisms at ASUS and malicious code reaching Linux distributions through XZ Utils both turned trusted software delivery into an attack path.
The Daemon Tools case matters because it extends that pattern to a widely used utility application, with malicious updates reportedly distributed over a month rather than through a one-off malicious download.
First-order effects
Daemon Tools users who received the affected updates face an immediate endpoint-security and remediation problem, since the trusted updater reportedly delivered backdoored software.
Daemon Tools’ distribution and update channel becomes the central incident surface: its release integrity, affected versions, and customer trust are directly implicated.
Second-order effects
Security teams will have reason to treat software-updater telemetry and installed Daemon Tools versions as incident-response inputs, rather than assuming signed or routine updates are inherently safe.
Other utility-software vendors and their customers face added pressure to tighten build, signing, and release-channel controls, as compromise of a peripheral tool can create broad endpoint exposure.
Third-order effects
If similar incidents persist, software supply-chain assurance will increasingly depend on verifiable release provenance and rapid revocation or rollback capabilities, not simply on users keeping software current.
The pattern shifts security risk from individual applications’ features toward the systems that build and distribute them; the scale of that shift depends on whether vendors can make update-channel compromise rarer and more quickly detectable.
The trend: This is another data point in the shift from exploiting software flaws to compromising the trusted software supply chain and its update paths.
Furthermore, we observed just one of the organizations to receive a unique RAT that is able to inject payloads and can use a wide range of protocols for C2 server communications - including WSS, QUIC, DNS and HTTP/3. Analysis of this implant is currently ongoing. [6/7]
However, we also observed hands-on activities for just about a dozen victim organizations - this indicates that this supply chain attack is a targeted one. These victims received a minimalistic backdoor, designed for downloading files and running shellcode payloads. [5/7] [image]
The malicious DAEMON Tools installers have been distributed since the release of version 12.5.0.2421. At the time of writing, the latest versions of this software remain infected. All installers are signed with legitimate certificates belonging to the software developers. [2/7] […
We observed the attackers using this backdoor for deploying further payloads to infected machines. In most cases, we observed attempted deliveries of an implant that conducts system information collection. Curiously, this implant contains strings in Chinese. [4/7] [image]
The DAEMON Tools executables delivered by malicious installers contain a backdoor which runs at the executable initialization stage. This backdoor is responsible for making GET requests to a C2 server to retrieve shell commands and further execute them. [3/7] [image]
Together with @bzvr_, @2igosha and Anton Kargin, we identified that the DAEMON Tools software has been compromised in a complex supply chain attack since April 8. We see thousands of infections across 100+ countries. If you use DAEMON Tools, run a malware scan immediately! [1/7] …
Given that this supply chain attack is highly complex, we urge everyone who uses DAEMON Tools to isolate their machines and initiate a security sweep to ensure protection against malware. You can refer to the IoCs that we published in our blogpost, https://securelist.com/.... [7/…