News
Daemon Tools Supply Chain Attack: Chinese Hackers Backdoored Official Installers for a Month
Kaspersky discovered that DAEMON Tools versions 12.5.0.2421–12.5.0.2434 were trojanized since April 8, delivering backdoors to thousands of systems across 100+ countries via the official website. The malware supports HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3 C2 protocols. While widespread, second-stage payloads hit only ~12 high-value targets in government, scientific, and manufacturing sectors. Evidence points to a Chinese-speaking adversary. Clean version 12.6 released May 5.
Source
↳ Follow the thread