Kaspersky Discovers Supply Chain Attack on Daemon Tools Website

Kaspersky Discovers Supply Chain Attack on Daemon Tools Website

First seen 6 Jun 2026, 11:24 UTC AnalyticsinsightDigitalterminal.In 99% similarity 71.0

Article Content

Browse articles
ThreatCluster

Kaspersky's Global Research and Analysis Team identified a supply chain attack on the official Daemon Tools website, affecting software versions 12.5.0.2421 and later. The attack, ongoing since April 8, 2026, involves a compromised installer that delivers backdoor malware, allowing remote control of infected devices. The malware was concealed using a valid developer digital certificate, exploiting user trust in signed software. The attack has impacted systems in over 100 countries, with significant concentrations in Russia, Brazil, and several European nations. Approximately 10% of affected systems belong to businesses, increasing risks for corporate networks. Kaspersky observed additional payloads being deployed on a small number of targeted machines across various sectors. The campaign has not yet been attributed to any known threat actor. Kaspersky has notified the software developer for remediation actions.

Key Points: • Ongoing supply chain attack on Daemon Tools since April 8, 2026. • Malware delivered via compromised installer with a valid digital certificate. • Approximately 10% of affected systems belong to businesses, heightening enterprise risk.

ThreatCluster AI

Timeline

2026-04-08
Supply chain attack initiated
Threat actors began distributing compromised Daemon Tools software through the official website.
Analyticsinsight
2026-06-05
Kaspersky reports findings
Kaspersky disclosed the ongoing attack, detailing the methods and impact on users worldwide.
Analyticsinsight
2026-06-06
Digital Terminal coverage
Digital Terminal published a report on Kaspersky's findings, confirming the attack's scope and implications.
Digitalterminal.In

Community

Browse all →

Tracked Entities in This Story