Kaspersky says Daemon Tools, a widely used app for mounting disk images, was backdoored on April 8 in a monthlong compromise that has pushed malicious updates
Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates …
Ars TechnicaDan Goodin
Context & Ripple Effects
The report sits alongside prior Kaspersky findings involving compromised distribution channels, notably ASUS’s live-update tool, and malicious code reaching major Linux distributions through XZ Utils. The common thread is trusted software delivery becoming the route into otherwise legitimate user environments.
It also follows reporting on weaponized legitimate open-source utilities, underscoring that familiar administrative and productivity software can become an access point when its release pipeline is compromised.
First-order effects
Daemon Tools users that installed affected updates may have received malicious code through a channel they normally trust, making remediation and identification of affected installations immediate priorities.
The software’s publisher and downstream distributors face an urgent need to halt or replace compromised update paths and establish which releases were exposed during the reported monthlong incident.
Second-order effects
Organizations that allow Daemon Tools will need to review endpoint inventories and software-update controls rather than treating signed or vendor-delivered updates as sufficient evidence of safety.
Security teams and competing software vendors face added pressure to monitor update behavior and validate release integrity, especially for broadly deployed utility software.
Third-order effects
Repeated compromises spanning vendor updaters, widely distributed utilities, and open-source components point to software supply-chain assurance becoming a core security control rather than a release-engineering detail.
If this pattern persists, buyers may increasingly evaluate software suppliers on their ability to secure build and update systems, not only on the features of the application itself.
The trend: The incident is another data point in the shift from exploiting individual endpoints to compromising trusted software distribution channels that can reach many users at once.
The malicious DAEMON Tools installers have been distributed since the release of version 12.5.0.2421. At the time of writing, the latest versions of this software remain infected. All installers are signed with legitimate certificates belonging to the software developers. [2/7] […
We observed the attackers using this backdoor for deploying further payloads to infected machines. In most cases, we observed attempted deliveries of an implant that conducts system information collection. Curiously, this implant contains strings in Chinese. [4/7] [image]
Together with @bzvr_, @2igosha and Anton Kargin, we identified that the DAEMON Tools software has been compromised in a complex supply chain attack since April 8. We see thousands of infections across 100+ countries. If you use DAEMON Tools, run a malware scan immediately! [1/7] …
Furthermore, we observed just one of the organizations to receive a unique RAT that is able to inject payloads and can use a wide range of protocols for C2 server communications - including WSS, QUIC, DNS and HTTP/3. Analysis of this implant is currently ongoing. [6/7]
However, we also observed hands-on activities for just about a dozen victim organizations - this indicates that this supply chain attack is a targeted one. These victims received a minimalistic backdoor, designed for downloading files and running shellcode payloads. [5/7] [image]
The DAEMON Tools executables delivered by malicious installers contain a backdoor which runs at the executable initialization stage. This backdoor is responsible for making GET requests to a C2 server to retrieve shell commands and further execute them. [3/7] [image]
Given that this supply chain attack is highly complex, we urge everyone who uses DAEMON Tools to isolate their machines and initiate a security sweep to ensure protection against malware. You can refer to the IoCs that we published in our blogpost, https://securelist.com/.... [7/…
Every single piece of code can put your crypto funds at risk if you are still relying on a software wallet to keep your keys safe in 2026. Get a freaking hardware wallet or a dedicated device for crypto!
Most of you have probably already seen the reports about the DAEMON Tools supply chain compromise According to Kaspersky, the campaign has been active since April 8 and affected victims in more than 100 countries On our side, we took the published indicators and turned them [imag…
Kaspersky has uncovered a backdoor embedded in the official Windows installer of Daemon Tools, a widely used disc imaging application. Security researchers believe Chinese-speaking hackers carried out a supply chain attack that began on April 8, compromising thousands of [image]
More: Kaspersky says the attack is still ongoing, suggesting the suspected Chinese hackers can still plant malware on any computer running a vulnerable version of Daemon Tools. — A rep. for Disc Soft, which makes the Daemon Tools software, told me it was aware of the report and…
I heard more from Disc-Soft, the maker of Daemon Tools, which was backdoored by suspected Chinese-language hackers and used to compromise thousands of users. Disc-Soft tells me the backdoor was “limited to the free DAEMON Tools Lite” and v12.6 removes the backdoor; investigation…