Daemon Tools Compromised in Prolonged Supply-Chain Attack

A significant security breach has affected the popular Daemon Tools application, leading to the distribution of malicious updates.

3 min readTechnology

The Daemon Tools application, known for its ability to mount disk images, has been compromised in a supply-chain attack that lasted for a month. According to Kaspersky, the cybersecurity firm that uncovered the breach, the attack began on April 8 and was still ongoing at the time of their report. The malicious updates were delivered through installers that were signed with the official digital certificate of the developer, making it difficult for users to detect the threat. The affected versions, specifically those running on Windows, include versions 12.5.0.2421 to 12.5.0.2434. The malware embedded within these versions activates upon system startup. The initial payload of the malware gathers sensitive information such as MAC addresses, hostnames, and installed software, sending this data to a server controlled by the attackers. The breach has impacted thousands of systems across over 100 countries, with a select few, approximately 12, linked to organizations in retail, government, and manufacturing receiving additional payloads, indicating targeted attacks.

Technology