DAEMON Tools Software Compromised in Targeted Malware Attack
A new supply chain attack has hit DAEMON Tools software, compromising its installers and distributing malicious payloads. Kaspersky researchers revealed that since April 8, 2026, installers from the legitimate DAEMON Tools website have been tampered with, affecting versions 12.5.0.2421 to 12.5.0.2434.
The attack impacts users in over 100 countries, including Russia, Brazil, and Turkey, with a focus on organizations in retail, government, and manufacturing sectors. Although thousands of infection attempts were observed, follow-on malware was delivered to only a dozen hosts, indicating a targeted approach.
To protect against such attacks, users should immediately isolate any systems with DAEMON Tools installed and conduct thorough security checks. The current risk level of this malware incident is deemed High, reflecting the sophisticated nature of the attackers and the potential for significant harm.
Source: View Original Report
