Daemon Tools, a Windows application for mounting disk images, was backdoored in a supply-chain attack that began on April 8 and pushed malicious updates from the developer's own servers, according to a report by security firm Kaspersky. Thousands of machines in more than 100 countries were targeted in the campaign, which remained active as of the report's publication.
Installers signed with the developer's official digital certificate and downloaded from the Daemon Tools website infected Daemon Tools executables, causing malware to run at boot time. Affected releases are versions 12.5.0.2421 through 12.5.0.2434, and only the Windows builds appear to be compromised.
The infected installers carry an initial payload that collects MAC addresses, hostnames, DNS domain names, running processes, installed software, and system locales, transmitting the data to an attacker-controlled server. About 10% of affected systems belong to businesses and organizations, with infected machines concentrated in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.
Most compromised machines received only the information collector. A follow-on payload was delivered to roughly a dozen machines belonging to government, scientific, manufacturing, and retail organizations in Russia, Belarus, and Thailand. That second-stage tool is a minimalistic backdoor capable of executing commands, downloading files, and running shellcode payloads in memory.
A more complex backdoor dubbed QUIC RAT was installed on a single machine at an educational institution in Russia. QUIC RAT can inject payloads into the notepad.exe and conhost.exe processes and supports command-and-control communication over HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3. The intent of the attacker, whether for cyberespionage or big game hunting, is currently unclear.
Kaspersky researchers wrote that the attack was executed with a high degree of sophistication. "Based on our long-term experience of analyzing supply chain attacks, we can conclude that attackers orchestrated the DAEMON Tools compromise in a highly sophisticated manner," they wrote. "For example, the time it took to detect this attack, which turned out to be about one month, is comparable to the 3CX supply chain attack which we researched together with the cybersecurity community in 2023."
Kaspersky's visibility into the campaign is based solely on telemetry from its own products. The firm recommended that Daemon Tools users scan their machines with reputable antivirus software and check for indicators of compromise listed in its post. For advanced users, Kaspersky recommended monitoring suspicious code injections into legitimate system processes, especially from executables launched from publicly accessible directories such as Temp, AppData, or Public.
forum Comments (0)
No comments yet. Be the first to comment.