Attackers compromised Daemon Tools software to deliver backdoors
ID: 86eafe4b-37d0-5191-a7ca-0596f3651fe9
STIX ID: report--86eafe4b-37d0-5191-a7ca-0596f3651fe9
Feed Name: Help Net Security
Threat Score
Kaspersky researchers found that the official Daemon Tools download site served legitimately signed, trojanized installers (April 8, 2026 onward) that installed a .NET information collector used to profile systems and selectively deploy additional backdoors (including QUIC RAT); infections were observed worldwide with targeted secondary deployments against several organizations, the vendor has released a clean build and launched an investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
