Suspected Backdoor Found in Daemon Tools Attack
2 min read
A new cybersecurity alert is raising concerns for thousands of Windows users. Researchers at Kaspersky say they have uncovered a hidden backdoor inside the widely used disc imaging software Daemon Tools—and the attack may already be affecting systems around the world.
According to the security firm, data gathered from devices running its antivirus software points to a “widespread” campaign. The attack appears to be targeting Windows machines that have Daemon Tools installed, potentially putting thousands of users at risk.
Kaspersky’s investigation suggests the attackers are likely a Chinese-speaking hacking group.
This conclusion is based on patterns found in the malware’s code and behavior. Once inside a system, the attackers used the backdoor to install additional malicious software. So far, at least a dozen confirmed cases have been identified across industries such as retail, manufacturing, scientific research, and even government networks.
Interestingly, while the overall campaign is broad, the follow-up attacks appear more focused. Kaspersky noted that the selection of compromised systems hints at a targeted effort. The affected organizations are located in countries including Russia, Belarus, and Thailand.
The backdoor was first discovered on April 8, marking the start of what researchers now believe is an ongoing operation. Despite being alerted, the developer behind Daemon Tools—Disc Soft—has not confirmed whether any fixes or actions have been implemented. This raises concerns that the threat could still be active.
Security experts warn that this incident fits into a growing trend of “supply chain attacks.” Instead of targeting users directly, hackers compromise trusted software providers. By injecting malicious code into legitimate applications or updates, they can quietly spread malware to a large number of users at once.
Similar incidents have surfaced in recent months. Earlier this year, attackers linked to China reportedly compromised Notepad++ to distribute malware. Another case involved the website of CPUID, known for tools like HWMonitor and CPU-Z, which was used to target unsuspecting visitors.
Further raising alarm, independent checks of the Daemon Tools installer using VirusTotal indicated the presence of the backdoor. However, it remains unclear whether the macOS version of the software or other products from Disc Soft have been affected.
In a brief response, a Disc Soft representative acknowledged the issue and said the company is actively investigating. While specific details are still unclear, the company claims it is working to assess risks and secure its software.
For now, users are advised to stay cautious, keep their systems updated, and monitor any unusual activity—especially if they have recently installed or updated Daemon Tools.
Also read : Nadella Signals Microsoft Will ‘Exploit’ New OpenAI Deal
