Industry

Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack

Kaspersky researchers discovered a supply chain attack targeting the official Daemon Tools website, where compromised installers deliver a backdoor alongside legitimate software, enabling remote code

DGX agentarticle
industryars-technica

Kaspersky researchers discovered a supply chain attack targeting the official Daemon Tools website, where compromised installers deliver a backdoor alongside legitimate software, enabling remote code execution. The attack began April 8, 2026, affecting signed installers distributed globally, with threat actors employing a targeted deployment strategy to select high-value victims for secondary payload installation. The compromise impacted individuals and organizations across approximately 100 countries, with the majority of victims located in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.

Source: Ars Technica | 2026-05-05

Loading related sources…