logo

What JDownloader and Daemon Tools reveal about software distribution trust

ID: 015563d5-7729-576e-a3f2-c8d8f80ea70b

STIX ID: report--015563d5-7729-576e-a3f2-c8d8f80ea70b

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

...
...

This report describes two supply-chain attacks in 2026: a 24-hour compromise of JDownloader installers via a website ACL link-swap that delivered unsigned Python RATs and persisted via a malicious root certificate, and a month-long trojanization of Daemon Tools signed installers (versions 12.5.0.2421–12.5.0.2434) that deployed multi-stage backdoors and an advanced implant (QUIC RAT) to selected high-value targets across more than 100 countries. The incidents demonstrate how trusted distribution channels and valid signatures can be abused, detail observed behaviors and affected components, and recommend Zero Trust controls (deny-by-default execution, allowlisting, ringfencing, controlled deployment) to mitigate similar supply-chain risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.