DAEMON Tools Confirms Supply Chain Attack Distributing Windows Malware
DAEMON Tools, a popular virtual drive software, has confirmed a significant supply chain security incident after antivirus provider Kaspersky detected malicious versions of its software being distributed through the official website. The attack, which began on April 8, involved hackers hijacking downloads for DAEMON Tools Lite versions 12.5.0.2421 to 12.5.0.2434. These compromised installers contained rigged executables designed to deliver a backdoor to Windows PCs. Kaspersky reported thousands of infection attempts across more than 100 countries, with victims primarily located in Russia, Brazil, Turkey, and several European nations. Although the malware spread widely, further-stage payloads were deployed to only a dozen machines belonging to retail, scientific, government, and manufacturing sectors, suggesting a targeted approach. Evidence points to a Chinese-speaking hacker group, and the malicious files were digitally signed by the developer, AVB Disc Soft. In response, DAEMON Tools removed the compromised files, launched an internal investigation, and released a clean version 12.6. The company stated that other products like DAEMON Tools Ultra remain safe. Users are urged to uninstall affected versions and perform full system scans.
Wire timeline
DAEMON Tools Confirms Supply Chain Attack Distributing Windows Malware
DAEMON Tools, a popular virtual drive software, has confirmed a significant supply chain security incident after antivirus provider Kaspersky detected malicious versions of its software being distributed through the official website. The attack, which began on April 8, involved hackers hijacking downloads for DAEMON Tools Lite versions 12.5.0.2421 to 12.5.0.2434. These compromised installers contained rigged executables designed to deliver a backdoor to Windows PCs. Kaspersky reported thousands of infection attempts across more than 100 countries, with victims primarily located in Russia, Brazil, Turkey, and several European nations. Although the malware spread widely, further-stage payloads were deployed to only a dozen machines belonging to retail, scientific, government, and manufacturing sectors, suggesting a targeted approach. Evidence points to a Chinese-speaking hacker group, and the malicious files were digitally signed by the developer, AVB Disc Soft. In response, DAEMON Tools removed the compromised files, launched an internal investigation, and released a clean version 12.6. The company stated that other products like DAEMON Tools Ultra remain safe. Users are urged to uninstall affected versions and perform full system scans.
PCMag.com - Technology Product Reviews, News, Prices & Tips