Trojanized Tools: DAEMON Tools Supply Chain Attack Compromises Global Systems
ID: e8325163-c023-532a-bcac-68b3c241bf1c
STIX ID: report--e8325163-c023-532a-bcac-68b3c241bf1c
Feed Name: securityonline.info
Kaspersky uncovered a sophisticated supply-chain attack in which legitimate DAEMON Tools installers (versions 12.5.0.2421–12.5.0.2434) were trojanized and signed with valid developer certificates starting 8 April 2026; infected startup binaries activate a backdoor that communicates with a typosquatted domain, enabling PowerShell-based payloads and staged deployment of a selective backdoor and a QUIC RAT to high-value government, scientific, and manufacturing targets, while thousands of users worldwide experienced initial infection vectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
