A new report from Kaspersky reveals a particularly worrying development in cybersecurity, with government, scientific, manufacturing being and retail organizations targeted by an evolving attack on the software supply chain. The incident concerns the popular Daemon Tools, which has been found to have a sophisticated backdoorembedded in versions distributed from the company's official website.

The case highlights once again how vulnerable even trusted software distribution chains can prove to be, when attackers manage to infiltrate the update or installation mechanism, affecting thousands of end users without being immediately noticed.
See also: Google attributes Axios Supply Chain Attack to UNC1069
The Daemon Tools supply chain attack
According to Kaspersky's analysis, the attack appears to have been organized with particular precision and persistence, as it affects Daemon Tools versions from 12.5.0.2421 to 12.5.0.2434, which were released after April 8. These versions contained malicious code, which was embedded directly into the executable files software's. AVB Disc Soft, the creator of Daemon Tools, has already been informed of the incident, while the threat remains active.
Modification of signed files and technical penetration
Of particular interest is the fact that the attackers did not limit themselves to external interference, but modified three key binaries of the software: DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe. All of these files were digitally signed with valid AVB Disc Soft certificates, which significantly increased their credibility in the eyes of security systems and users.
Integrating the malicious code into the startup mechanism allows the backdoor to be automatically activated every time the system starts, making the threat persistent and difficult to detect.
Communication and order execution mechanism
The technical operation of the backdoor is based on a mechanism for communicating with a remote server via a domain registered using typosquatting. This domain was created on March 27 and is used to send commands to the infected system.

When the backdoor is activated, the system makes requests to the specified server, which in turn can return commands. These commands allow additional malicious payload, enhancing the functionality of the attack.
Geographic spread and extent of infection
Kaspersky says the attack has affected thousands of systems in more than 100 countries, with a significant presence in Brazil, China, France, Germany, Italy, Russia, Spain and Turkey. Around 10% of the infected systems belong to businesses and organizations, suggesting that the campaign is not limited to individual users.
See also: Axios Supply Chain Attack: Malicious versions distribute RAT
Targeted attacks and second stage infection
Although the initial infection was widespread, data suggests that the attackers were more targeted. Based on the information gathered from the first backdoor, specific systems were identified, which were then infected with a second, lighter but more specialized backdoor.
In total, just a dozen systems across government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand appear to have been affected by this second stage. This observation reinforces the assessment of targeted espionage activity.
QUIC RAT usage and unclear motivations
In a more advanced stage of the attack, the backdoor was used to install the malicious QUIC RAT in an educational institution in Russia. This remote access tool allows attackers to take full control of the system, significantly expanding their monitoring and data interception capabilities.
Despite the technical analysis, the motives behind the attack remain unclear. Kaspersky notes that the methodology clearly indicates a targeted approach, but it is not yet certain whether it is cyberespionage or financially motivated.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Open VSX: Supply Chain attack distributes GlassWorm via compromised dev account

Conclusions and implications for cybersecurity
The Daemon Tools incident highlights the dangers of supply chain attacks, where even trusted software can be turned into a vehicle for malicious activity. The ability to embed a backdoor into signed files shows that traditional methods of trusting software are no longer sufficient.
As attacks become increasingly complex and multi-layered, the need for advanced detection systems, continuous integrity checks, and stronger supply chain oversight becomes more imperative than ever.
