logo

Hackers Abuse DAEMON Tools Distribution Channel to Deliver Malicious Payloads

ID: dc38c049-bfe4-5d9b-a9e6-c5ee07fa7466

STIX ID: report--dc38c049-bfe4-5d9b-a9e6-c5ee07fa7466

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Divya

...
...

Supply‑chain compromise of DAEMON Tools installers (v12.5.0.2421–12.5.0.2434) delivering trojanized, legitimately signed binaries that activate a hidden backdoor contacting https://env-check.daemontools.cc; multi‑stage payloads include envchk.exe (information collector), cdg.exe (RC4 in‑memory loader), and a heavily obfuscated QUIC RAT used for targeted espionage. The report provides file hashes, modified binary hashes, filenames, a C2 domain and IP, and notes broad distribution across 100+ countries with selective deployment to high‑value organizations in retail, scientific, government, and manufacturing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.