Supply Chain Breach Hits DAEMON Tools Installers in Global Backdoor Campaign

Listen to this Post

Featured Image

Introduction

A new software supply-chain attack has compromised one of the long-standing Windows utilities, DAEMON Tools, turning trusted installers into a delivery mechanism for stealth malware. The attack, which began on April 8, spread through the official distribution channel and affected users in more than 100 countries. While thousands of systems were initially infected, only a small subset received advanced follow-up payloads, suggesting a carefully controlled and highly targeted cyber operation aimed at high-value organizations.

Summary of the Incident

Hackers successfully trojanized DAEMON Tools installers distributed via the official website, embedding malicious code into legitimate signed binaries without immediately breaking the software’s functionality. The compromised versions, ranging from 12.5.0.2421 to 12.5.0.2434, included altered components such as DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. Once installed, the software behaved normally on the surface, making detection difficult for both users and security tools. However, upon execution, the malicious code activated and established persistence on infected systems. This allowed attackers to maintain long-term access even after reboots. The malware first collected system-level information including hostnames, MAC addresses, process lists, installed applications, and locale settings. This data was then transmitted back to command servers for profiling and targeting decisions. From there, only selected victims received second-stage payloads. These payloads included lightweight backdoors capable of executing commands, downloading additional files, and running malicious code directly in memory to avoid detection. In one documented case involving a Russian educational institution, a more advanced payload known as QUIC RAT was deployed, offering multi-protocol communication and process injection capabilities. Kaspersky researchers confirmed the campaign is still active and described it as highly sophisticated, noting it evaded detection for nearly a month. The attack impacted organizations across retail, manufacturing, government, and scientific sectors, with victims identified in Russia, Belarus, and Thailand. Although attribution remains unconfirmed, technical indicators suggest a possible Chinese-speaking threat actor. The compromised installer versions indicate a structured and controlled modification of software supply chains rather than random malware distribution. DAEMON Tools, once widely used in the 2000s for virtual disk mounting, has become a niche utility, but still exists in environments where disk image management is required. Despite its reduced popularity, its trusted reputation made it an ideal vector for silent infiltration. Security analysts also warn that supply-chain attacks have become increasingly frequent in 2026, with similar incidents observed involving other widely used tools and platforms. The stealth and precision of this operation highlight a growing trend of attackers focusing on trusted software ecosystems instead of direct system exploitation.

What Undercode Say:

This attack reflects a clear shift in modern cyber intrusion strategy
Instead of breaking systems directly, attackers are now compromising trust chains
DAEMON Tools was an ideal target because of its legacy trust and digital signatures

Signed malware bypasses many traditional antivirus heuristics

This significantly increases initial infection success rates

The multi-stage design shows operational maturity and resource planning

Mass infection followed by selective targeting reduces exposure risk

Only high-value systems receive second-stage payloads

This indicates intelligence-driven filtering rather than random spread

The use of system profiling suggests pre-exploitation reconnaissance

MAC addresses and process lists help attackers identify enterprise environments

QUIC RAT deployment shows escalation capability for priority targets

Memory-based execution reduces forensic traces on infected machines

Persistence mechanisms ensure long-term foothold even after reboots

The attack window of nearly one month without detection is critical

It highlights gaps in software supply chain monitoring tools

Even well-known utilities can become infection vectors

Organizations often overlook older software with assumed trust status

The geographic distribution suggests strategic targeting in specific regions

Government and educational institutions are clearly prioritized targets

The presence of multiple sectors shows broad reconnaissance reach

However, selective payload delivery confirms controlled exploitation logic

This reduces noise and avoids triggering mass detection systems

Attribution remains uncertain but linguistic analysis suggests Chinese-speaking operators

This is not definitive proof, only an indicator based on payload artifacts
Supply chain attacks are becoming a default strategy for advanced threat actors
The barrier for detection increases when legitimate installers are used

Security teams must now validate software integrity continuously

Traditional endpoint protection is insufficient alone

Behavioral detection and installation verification are becoming essential

The attack demonstrates patience, stealth, and modular payload design

The ecosystem trust model is being actively weaponized

Even minor utilities can become entry points for enterprise breaches
The trend of monthly supply chain attacks signals industrialization of the tactic

Attackers are prioritizing long dwell time over immediate impact

Silent infiltration is more valuable than rapid disruption

This campaign reinforces the need for software provenance tracking

Organizations must assume trusted installers can no longer be trusted by default
The attack is not isolated but part of a broader escalation pattern

Fact Checker Results

✅ Kaspersky did report a DAEMON Tools supply-chain compromise and ongoing activity
⚠️ Attribution to Chinese-speaking actors is suggested but not confirmed
❌ No verified evidence that QUIC RAT was deployed broadly across all victims

Prediction

Future supply-chain attacks will likely target even more obscure but widely deployed utilities 🔮
We can expect increased use of signed malware to bypass enterprise defenses
Selective payload delivery will become more common to avoid detection triggers
Organizations may begin enforcing strict software integrity verification at installation time

🕵️‍📝Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon