Close Menu
    What's Hot

    Demonstrators Cannot Be Forced to Take Down ‘86-47’ Flag, Judge Rules

    Trump Says Israel, Hezbollah to Halt Attacks as Iran Talks Continue

    Mette Frederiksen Forms New Government in Denmark

    Facebook X (Twitter) Instagram
    Trending
    • Demonstrators Cannot Be Forced to Take Down ‘86-47’ Flag, Judge Rules
    • Trump Says Israel, Hezbollah to Halt Attacks as Iran Talks Continue
    • Mette Frederiksen Forms New Government in Denmark
    • Trump Stands to Gain a Key Ally in Colombia’s Upcoming Election
    • Anthropic’s browser agent got hijacked 31.5% of the time before safeguards engaged
    • French Open: Aryna Sabalenka beats Naomi Osaka to reach quarter-finals at Roland-Garros | Tennis News
    • England vs India: Danni Wyatt-Hodge expecting ‘fireworks’ from struggling opening partner in T20 series decider | Cricket News
    • The Google Pixel Watch 5 may have been spoiled by… the creator of Borderlands
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware

    adminBy adminMay 5, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMay 05, 2026Endpoint Security / Software Security

    DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware

    A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from Kaspersky.

    “These installers are distributed from the legitimate website of DAEMON Tools and are signed with digital certificates belonging to DAEMON Tools developers,” Kaspersky researchers  Igor Kuznetsov, Georgy Kucherin, Leonid Bezvershenko, and Anton Kargin said.

    The installers have been trojanized since April 8, 2026, with versions ranging from 12.5.0.2421 to 12.5.0.2434 identified as compromised as part of the incident. The supply chain attack is active as of writing. AVB Disc Soft, the developer of the software, has been notified of the breach.

    Specifically, three different components of DAEMON Tools have been tampered with –

    • DTHelper.exe
    • DiscSoftBusServiceLite.exe
    • DTShellHlp.exe
    Cybersecurity

    Any time one of these binaries is launched, which typically happens during system startup, an implant is activated on the compromised host. It’s designed to send an HTTP GET request to an external server (“env-check.daemontools[.]cc”) – a domain registered on March 27, 2026 – in order to receive a shell command that’s run using the “cmd.exe” process.

    The shell command, for its part, is used to download and run a series of executable payloads. These include –

    • envchk.exe, a .NET executable to collect extensive system information.
    • cdg.exe and cdg.tmp, the former of which is a shellcode loader responsible for decrypting the contents of the second file and launching a minimalist backdoor that contacts a remote server to download files, run shell commands, and execute shellcode payloads in memory.

    The Russian cybersecurity company said it observed several thousand infection attempts involving DAEMON Tools in its telemetry, impacting individuals and organizations in more than 100 countries, such as Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. However, the next-stage backdoor has been delivered only to a dozen hosts, indicating a targeted approach.

    The systems that received the follow-on malware have been flagged as belonging to retail, scientific, government, and manufacturing organizations in Russia, Belarus, and Thailand. What’s more, one of the payloads delivered via the backdoor is a remote access trojan dubbed QUIC RAT. The use of the C++ implant has been recorded against a lone victim: an educational institution located in Russia.

    “This manner of deploying the backdoor to a small subset of infected machines clearly indicates that the attacker had intentions to conduct the infection in a targeted manner,” Kaspersky said. “However, their intent – whether it is cyberespionage or ‘big game hunting’ – is currently unclear.”

    The malware supports a variety of command-and-control (C2) protocols, including HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3, and comes equipped with capabilities to inject payloads into legitimate “notepad.exe” and “conhost.exe” processes.

    The activity has not been attributed to any known threat actor or group. But evidence points to it being the work of a Chinese-speaking adversary based on an analysis of the artifacts observed.

    Cybersecurity

    The DAEMON Tools compromise is the latest in a growing list of software supply chain incidents in the first half of 2026, and follows similar high-profile breaches involving eScan in January, Notepad++ in February, and CPUID in April.

    “A compromise of this nature bypasses traditional perimeter defenses because users implicitly trust digitally signed software downloaded directly from an official vendor,” Kucherin, senior security researcher at Kaspersky GReAT, said in a statement shared with The Hacker News.

    “Because of that, the DAEMON Tools attack has gone unnoticed for about a month. This period of time, in turn, indicates that the threat actor behind this attack is sophisticated and has advanced offensive capabilities. Given the high complexity of the compromise, it is thus of paramount importance for organizations to isolate machines having Daemon Tools software installed, as well as to conduct security sweeps to prevent further spreading of malicious activities inside corporate networks.”

    attack Chain Compromises DAEMON Installers Malware official Supply Tools
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleRuto projects $1 billion Kenya–Tanzania trade milestone in 2026 as ties deepen – The Mail & Guardian
    Next Article The Next Call Of Duty Is Not Coming To PS4 (Or Presumably Xbox One)
    admin
    • Website

    Related Posts

    Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

    June 1, 2026

    Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts – Krebs on Security

    June 1, 2026

    OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

    June 1, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Demonstrators Cannot Be Forced to Take Down ‘86-47’ Flag, Judge Rules

    Trump Says Israel, Hezbollah to Halt Attacks as Iran Talks Continue

    Mette Frederiksen Forms New Government in Denmark

    Trump Stands to Gain a Key Ally in Colombia’s Upcoming Election

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by