logo

DAEMON Tools Breach Used to Spread Malware in Supply Chain Attack

ID: aa500583-fcfb-52a6-b40f-85faaaeae1d0

STIX ID: report--aa500583-fcfb-52a6-b40f-85faaaeae1d0

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: AnuPriya

...
...

A trojanized supply-chain attack compromised DAEMON Tools installers distributed from the official site (April 8, 2026), embedding a CRT-initialization backdoor that contacts a typosquatted C2 domain; researchers observed a three-stage payload chain (envchk.exe information collector, cdg.exe backdoor, and a QUIC RAT) with thousands of infection attempts across 100+ countries and targeted backdoor deployments against organizations in select countries. Indicators provided include the C2 domain env-check.daemontools.cc, IP 38.180.107.76, SHA1 hashes for installers and payloads, and suspicious file paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.