logo

DAEMON Tools trojanized in supply-chain attack to deploy backdoor

ID: 7a63bb1c-baef-5f5f-a68f-1e119aeaaf1d

STIX ID: report--7a63bb1c-baef-5f5f-a68f-1e119aeaaf1d

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Bill Toulas

...
...

Kaspersky and reporting reveal a supply-chain attack that trojanized DAEMON Tools installers (versions 12.5.0.2421–12.5.0.2434) to deploy a first-stage info-stealer and, for selected victims, a second-stage backdoor capable of executing commands and loading additional payloads; at least one target received the more advanced QUIC RAT. Thousands of systems across 100+ countries downloaded the compromised installers since April 8, while only a dozen machines received follow-on implants, indicating a broad infection vector with targeted secondary compromises and ongoing active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.