Vendor Says Daemon Tools Supply Chain Attack Contained

https://www.securityweek.com/wp-content/uploads/2024/01/Supply-Chain-Software-Attack.jpg

Daemon Tools developer Disc Soft has confirmed falling victim to an intrusion that led to a targeted supply chain attack.

The incident came to light earlier this week, when Kaspersky warned that thousands of computers might have been infected with malware after downloading trojanized versions of Daemon Tools from the official website.

According to Kaspersky, Chinese-speaking threat actors injected Daemon Tools iterations released between April 8 and May 5 with code designed to download and execute an information collector.

Out of thousands of infected machines, the attackers then selected roughly a dozen to infect with a backdoor, and targeted a Russian educational institution with a second, more complex backdoor as well.

The initial backdoor, Kaspersky says, was deployed on systems of government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand.

On Wednesday, Disc Soft confirmedthat hackers compromised certain installation packages, but said that the impact was limited...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE