Apps & Consumer
Chinese hackers target Daemon Tools in supply chain attack
Kaspersky identified a malicious backdoor in Daemon Tools, launching a widespread, active supply chain attack that has targeted thousands of Windows computers.
The Russian cybersecurity company Kaspersky has identified a malicious backdoor in Daemon Tools, a popular and long-running Windows disc imaging software. The discovery has exposed a widespread supply chain attack—a cyberattack that targets a software developer to compromise their users—which Kaspersky reports is still active. According to data collected from computers running Kaspersky’s antivirus software, the ongoing campaign is actively targeting thousands of Windows computers that run the compromised disc imaging utility.
The backdoor was first detected on April 8. On Tuesday, Kaspersky reported data showing that while the attack is broad, the threat actors have also engaged in highly targeted operations. Specifically, the hackers used the backdoor to plant additional malware on a dozen computers. These compromised systems span sectors including retail, science, manufacturing, and government organizations. Kaspersky noted that the selection of these specific systems indicates a highly targeted effort within the broader campaign.
Based on an analysis of the malware, Kaspersky researchers linked the threat actors to a Chinese-language speaking group. The targeted organizations affected by the secondary malware infections are located in Russia, Belarus, and Thailand. Because the supply chain attack remains active, Kaspersky warned that the hackers retain the capability to deploy further malware to the thousands of systems currently running the compromised software.
Disc Soft, the developer of Daemon Tools, has acknowledged the security incident. When contacted for comment, a Disc Soft representative stated that the company is “aware of the report and are currently investigating the situation.” The representative emphasized the developer’s response, stating, “Our team is treating this matter with the highest priority and is actively working to assess and address the issue. At this stage, we are not in a position to confirm specific details referenced in the report. However, we are taking all necessary steps to remediate any potential risks and to ensure the security of our users”.
Why it matters
This incident highlights the growing risk of supply chain attacks, where hackers compromise legitimate software updates to gain access to thousands of systems simultaneously, bypassing traditional security perimeters.