DAEMON Tools Breach Used to Spread Malware in Supply Chain Attack
ID: aa500583-fcfb-52a6-b40f-85faaaeae1d0
STIX ID: report--aa500583-fcfb-52a6-b40f-85faaaeae1d0
Feed Name: Cyber Press
A trojanized supply-chain attack compromised DAEMON Tools installers distributed from the official site (April 8, 2026), embedding a CRT-initialization backdoor that contacts a typosquatted C2 domain; researchers observed a three-stage payload chain (envchk.exe information collector, cdg.exe backdoor, and a QUIC RAT) with thousands of infection attempts across 100+ countries and targeted backdoor deployments against organizations in select countries. Indicators provided include the C2 domain env-check.daemontools.cc, IP 38.180.107.76, SHA1 hashes for installers and payloads, and suspicious file paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
