logo

DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware

ID: 7f15661b-52cb-50dc-86a4-67e28fd8cb85

STIX ID: report--7f15661b-52cb-50dc-86a4-67e28fd8cb85

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Kaspersky discovered a supply-chain attack that trojanized DAEMON Tools installers (signed and served from the official site) between versions 12.5.0.2421–12.5.0.2434 beginning April 8, 2026, activating an implant that contacts env-check.daemontools.cc to fetch commands and deliver a multi-stage payload (envchk.exe, cdg.exe/cdg.tmp, and backdoors including QUIC RAT). Telemetry shows several thousand infection attempts across 100+ countries, with targeted second-stage backdoor deployment to about a dozen high-value hosts in retail, scientific, government, and manufacturing sectors; the malware supports many C2 channels and process injection, indicating a sophisticated adversary and active supply-chain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.