Digitalterminal.In
Kaspersky Discovers Supply Chain Attack on Daemon Tools Website
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Kaspersky's Global Research and Analysis Team identified a supply chain attack on the official Daemon Tools website, affecting software versions 12.5.0.2421 and later. The attack, ongoing since April 8, 2026, involves a compromised installer that delivers backdoor malware, allowing remote control of infected devices. The malware was concealed using a valid developer digital certificate, exploiting user trust in signed software. The attack has impacted systems in over 100 countries, with significant concentrations in Russia, Brazil, and several European nations. Approximately 10% of affected systems belong to businesses, increasing risks for corporate networks. Kaspersky observed additional payloads being deployed on a small number of targeted machines across various sectors. The campaign has not yet been attributed to any known threat actor. Kaspersky has notified the software developer for remediation actions.
Key Points: • Ongoing supply chain attack on Daemon Tools since April 8, 2026. • Malware delivered via compromised installer with a valid digital certificate. • Approximately 10% of affected systems belong to businesses, heightening enterprise risk.