Kaspersky identifies ongoing supply chain attack on official Daemon Tools website distributing backdoor malware

https://www.itvoice.in/wp-content/uploads/2026/06/Copy-of-Redington-2026-06-05T164423.374.jpg

Kaspersky’s Global Research and Analysis Team (GReAT) discovered an active supply chain attack targeting the official website of Daemon Tools, a widely used virtual drive emulation software. The compromised installer delivers malicious software alongside the legitimate application, granting threat actors the ability to execute arbitrary commands and remotely control infected devices.

During a recent telemetry study, researchers identified that threat actors have actively distributed the modified software directly through the vendor’s primary domain since April 8, 2026, successfully concealing the malware with a valid developer digital certificate. The malicious injection affects Daemon Tools version 12.5.0.2421 up through the current release. Kaspersky has notified AVB Disc Soft, the developer of Daemon Tools, so that remediation actions can be taken.

Because disk emulation software requires low-level system access to function properly, users routinely grant the application elevated administrative privileges during installation. This mechanism allows the embedded malware to secure a deep foothold...

Copyright of this story solely belongs to itvoice.in. To see the full text click HERE