HomeSecurityDAEMON Tools Supply Chain Attack: Government Organizations Targeted

DAEMON Tools Supply Chain Attack: Government Organizations Targeted

A new report from Kaspersky reveals a particularly worrying development in cybersecurity, with government, scientific, manufacturing being and retail organizations targeted by an evolving attack on the software supply chain. The incident concerns the popular Daemon Tools, which has been found to have a sophisticated backdoorembedded in versions distributed from the company's official website.

DAEMON Tools

The case highlights once again how vulnerable even trusted software distribution chains can prove to be, when attackers manage to infiltrate the update or installation mechanism, affecting thousands of end users without being immediately noticed.

See also: Google attributes Axios Supply Chain Attack to UNC1069

The Daemon Tools supply chain attack

According to Kaspersky's analysis, the attack appears to have been organized with particular precision and persistence, as it affects Daemon Tools versions from 12.5.0.2421 to 12.5.0.2434, which were released after April 8. These versions contained malicious code, which was embedded directly into the executable files software's. AVB Disc Soft, the creator of Daemon Tools, has already been informed of the incident, while the threat remains active.

Modification of signed files and technical penetration

Of particular interest is the fact that the attackers did not limit themselves to external interference, but modified three key binaries of the software: DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe. All of these files were digitally signed with valid AVB Disc Soft certificates, which significantly increased their credibility in the eyes of security systems and users.

Integrating the malicious code into the startup mechanism allows the backdoor to be automatically activated every time the system starts, making the threat persistent and difficult to detect.

Communication and order execution mechanism

The technical operation of the backdoor is based on a mechanism for communicating with a remote server via a domain registered using typosquatting. This domain was created on March 27 and is used to send commands to the infected system.

DAEMON Tools Supply Chain Attack: Government Organizations Targeted

When the backdoor is activated, the system makes requests to the specified server, which in turn can return commands. These commands allow additional malicious payload, enhancing the functionality of the attack.

Geographic spread and extent of infection

Kaspersky says the attack has affected thousands of systems in more than 100 countries, with a significant presence in Brazil, China, France, Germany, Italy, Russia, Spain and Turkey. Around 10% of the infected systems belong to businesses and organizations, suggesting that the campaign is not limited to individual users.

See also: Axios Supply Chain Attack: Malicious versions distribute RAT

Targeted attacks and second stage infection

Although the initial infection was widespread, data suggests that the attackers were more targeted. Based on the information gathered from the first backdoor, specific systems were identified, which were then infected with a second, lighter but more specialized backdoor.

In total, just a dozen systems across government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand appear to have been affected by this second stage. This observation reinforces the assessment of targeted espionage activity.

QUIC RAT usage and unclear motivations

In a more advanced stage of the attack, the backdoor was used to install the malicious QUIC RAT in an educational institution in Russia. This remote access tool allows attackers to take full control of the system, significantly expanding their monitoring and data interception capabilities.

Despite the technical analysis, the motives behind the attack remain unclear. Kaspersky notes that the methodology clearly indicates a targeted approach, but it is not yet certain whether it is cyberespionage or financially motivated.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Open VSX: Supply Chain attack distributes GlassWorm via compromised dev account

DAEMON Tools Supply Chain Attack: Government Organizations Targeted

Conclusions and implications for cybersecurity

The Daemon Tools incident highlights the dangers of supply chain attacks, where even trusted software can be turned into a vehicle for malicious activity. The ability to embed a backdoor into signed files shows that traditional methods of trusting software are no longer sufficient.

As attacks become increasingly complex and multi-layered, the need for advanced detection systems, continuous integrity checks, and stronger supply chain oversight becomes more imperative than ever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS