The images in this article were generated with artificial intelligence. How we publish
A recent report by Kaspersky confirms what cyber security teams already feared: the attackers committed official DAEMON Tools installers and, since April 8, distributed digitally signed software that included a first stage malware capable of installing a back door and filtering information from the machines concerned. The campaign is a classic example of a supply chain attack: confidence exploited in a legitimate installer to get massive access and, in some cases, access to high-value targets.
According to Kaspersky, the affected versions include specific numbers of branch 12.5 (from 12.5.0.2421 to 12.5.0.2434) and the compromised libraries were executable as DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe. The first module acts as a "info stealer" that collects data such as equipment name, MAC address, running processes and software installed to enable attackers to profile victims. On that basis, in just a dozen environments a second stage - light but powerful - was deployed capable of running commands, downloading additional loads and running code directly in memory; in at least one case the presence of the sophisticated QUIC RAT was observed.

The distribution by signed installers and persistence evades many initial detections: the digital signature gives a legitimate appearance that reduces the alarms of users and administrators, and the selective sampling of subsequent loads turns most infections into simple sensors that help to choose objectives of interest. That is why it is relevant that, although thousands of machines in more than 100 countries received the compromised installation, Only a few were targeted by the second stage, which suggests an interest in specific targets such as retail, educational, scientific and manufacturing organizations in countries such as Russia, Belarus and Thailand.
The practical implications are clear: any organization that has downloaded DAEMON Tools from the official site around those dates should take risk and act. The nature of the vector - utility software with legitimate use - shows that prevention cannot depend only on checking signatures or blocking applications by name; it requires detection controls, minimum exposure policies and rapid response processes.
If you are an administrator or a security officer, start with quickly identify the hosts that installed DAEMON Tools in or after 8 April and examine abnormal activity: unknown outgoing connections, unusual processes, execution in memory without associated file and changes in persistence. Obtain and implement the IoC and technical recommendations published by the Kaspersky and other sources analysis, and consider the immediate containment of suspicious equipment to avoid side movements and exfiltration.
In addition to isolating committed equipment, rotate credentials that may have been used in such machines, revoke certificates if necessary and perform forensic analysis with EDR or tools that support memory detection. To reduce false negatives, support research with public YARA / IOCs rules and network solutions that detect C2 patterns and abnormal downloads; also make sure the backups are complete before restoring systems.
For users and small organizations: if you need DAEMON Tools, download a verified copy from alternative channels recognized by the developing company (and check sums / signatures), or remove the application and replace functionality with more modern alternatives where possible. If you do not use virtual image mounted regularly, Uninstall the software and review the machine with an updated antivirus and memory detection tools.

This episode fits a broader trend: the almost monthly emergence of gaps in software supply chains this year shows that confidence in a legitimate package is no longer sufficient. Organizations should require their practical suppliers to publish SBOM, strict monitoring of the building process, rotation and protection of signature keys, and the adoption of frameworks such as SLSA to enhance the safety of the software life cycle. For practical guidance on risk management in the supply chain, see public resources such as those published by CISA: https: / / www.cisa.gov / supply-chain-risk-management.
For technical details and list of commitment indicators, Kaspersky analysis is a useful starting point: Kaspersky - DAEMON Tools backdoor. Response teams should collect local artifacts, compare with known IoC and coordinate notifications to suppliers and, where appropriate, regulatory authorities to meet incident reporting requirements.
In short, this incident reinforces two lessons that are already mandatory for modern cyberdefence: the trust in signed software is not absolute guarantee and the defense in depth is essential. Organizations that apply continuous software inventory, network segmentation, performance monitoring and well-tested response procedures will significantly reduce the impact of future commitments to the supply chain.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...