HomeTechnologyWidely used Daemon Tools disk app backdoored in monthlong supply-chain attack

Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack

TechnologyMay 5, 2026
2 min read
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack
Daemon Tools users: It's time to check your machines for stealthy infections, stat.
Reading Settings

Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates from the servers of its developer, researchers said Tuesday.

Kaspersky, the security firm reporting the supply-chain attack, said it began on April 8 and remained active as of the time its post went live. Installers that are signed by the developer’s official digital certificate and downloaded from its website infect Daemon Tools executables, causing the malware to run at boot time. Kaspersky didn’t explicitly say so, but based on technical details, the infected versions appear to be only those that run on Windows. Versions 12.5.0.2421 through 12.5.0.2434 are affected. Neither Kaspersky nor developer AVB could be contacted immediately for additional details.

Hard to defend against

Infected versions contain an initial payload that collects MAC addresses, hostnames, DNS domain names, running processes, installed software, and system locales. The malware sends them to an attacker-controlled server. Thousands of machines in more than 100 countries were targeted. Out of the many machines infected, about 12 of them, belonging to retail, scientific, government and manufacturing organizations, have received a follow-on payload—an indication the supply-chain attack targets select groups.

Read full article

Comments

Source: Ars Technica

Share this article

Related Articles

It’s time to address the looming crisis in entry-level work.
May 261 hour ago

It’s time to address the looming crisis in entry-level work.

Artificial intelligence has not so far produced a clean story of mass unemployment. Aggregate employment in developed countries remains broadly stable, and recent assessments have found limited eviden

technologyreview.com7 min read
Read More
Rethinking organizational design in the age of agentic AI
May 261 hour ago

Rethinking organizational design in the age of agentic AI

Amid rapidly growing adoption of enterprise-level AI agents, there’s a disconnect emerging between ambition and execution.  Although 85% of organizations say they want to be agentic within the ne

technologyreview.com8 min read
Read More