Switch language한국어
Back to the list

Popular Daemon Tools utility exploited in supply chain attack

TL;DR AI

Key summary

2 min read
  1. Official Daemon Tools installers were tampered with in a supply chain attack starting April 8, affecting versions 12.5.0.2421 to 12.5.0.2434.

  2. The malicious installers modified core binaries to launch a backdoor at startup, despite being downloaded from the vendor’s official site and signed.

  3. Kaspersky says infections were widespread, with thousands of systems impacted in more than 100 countries, including business networks.

  4. The campaign also enabled targeted follow-on intrusions in several countries and used infrastructure linked to QUIC RAT and a typosquatting domain.

Read the original