الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky Detects Supply Chain Attack on DAEMON Tools Website Distributing Backdoor Malware

During a recent telemetry study, researchers identified that threat actors have actively distributed the modified software directly through the vendor’s primary domain since April 8, 2026, successfully concealing the malware with a valid developer digital certificate. The malicious injection affects Daemon Tools version 12.5.0.2421 up through the current release. Kaspersky has notified AVB Disc Soft, the developer of Daemon Tools, so that remediation actions can be taken.
Because disk emulation software requires low-level system access to function properly, users routinely grant the application elevated administrative privileges during installation. This mechanism allows the embedded malware to secure a deep foothold within the host operating system, severely compromising device integrity. Specifically, attackers tampered with legitimate application binaries to execute malicious code at process startup and leveraged a legitimate Windows service to maintain persistence on the host.
Kaspersky telemetry indicates a widespread, global distribution of the compromised updates across more than 100 countries and territories. The majority of victims are located in Russia, Brazil, Türkiye, Spain, Germany, France, Italy, and China.
The analysis shows that 10% of the affected systems belong to businesses and organizations. While Daemon Tools is heavily adopted by consumers, its presence in corporate environments exposes enterprise networks to severe downstream risks.
On a small subset of just over ten machines — belonging to organizations in the retail, scientific, government, and manufacturing sectors — Kaspersky GReAT observed attackers manually deploying additional payloads, including a shellcode injector and previously unknown Remote Access Trojans (RATs). The narrow industry profile of these victims, combined with typos and inconsistencies in the executed commands, indicates that the follow-on activity is conducted hands-on against specifically chosen targets. While researchers identified Chinese-language artifacts within the malicious implants, the campaign is not currently attributed to any known threat actor.
“A compromise of this nature bypasses traditional perimeter defenses because users implicitly trust digitally signed software downloaded directly from an official vendor,” said Georgy Kucherin, senior security researcher at Kaspersky GReAT. “Because of that, the Daemon Tools attack has gone unnoticed for about a month. This period of time, in turn, indicates that the threat actor behind this attack is sophisticated and has advanced offensive capabilities. Given the high complexity of the compromise, it is thus of paramount importance for organizations to isolate machines having Daemon Tools software installed, as well as to conduct security sweeps to prevent further spreading of malicious activities inside corporate networks.”
Kaspersky actively detects and blocks the execution of the compromised installers. Researchers advise organizations to audit their networks for the presence of Daemon Tools Lite, isolate affected endpoints, and monitor for unauthorized command execution or lateral movement. Individual users should promptly uninstall the compromised application and run a thorough system scan to clear any persistent threats.
Read full research on Securelist.com.
In March 2026, a Kaspersky study found supply chain attacks were the most common cyberthreat businesses faced over the prior 12 months, yet only 9% of organizations ranked them as a top concern.
To mitigate the risks associated with software supply chain attacks, Kaspersky recommends organizations adopt the following security measures:
• Audit software supply chains: Before authorizing third-party applications for corporate environments, evaluate the vendor’s security track record, review their vulnerability disclosure data, and verify their compliance with industry security standards.
• Enforce strict procurement protocols: Mandate regular security audits for all deployed software and ensure any tools utilized by employees comply with the organization’s internal security policies and incident notification requirements.
• Restrict administrative privileges: Implement preventive frameworks, such as the principle of least privilege and zero-trust architecture. Limiting user access rights significantly reduces the potential blast radius if a trusted application is compromised and attempts to execute unauthorized commands.
• Deploy continuous infrastructure monitoring: Kaspersky recommends utilizing Extended Detection and Response (XDR) solutions, such as the Kaspersky Next product line. These tools provide real-time monitoring to identify anomalies in network traffic or unauthorized actions originating from implicitly trusted software.
• Update incident response playbooks: Ensure organizational security strategies explicitly account for supply chain breaches. Playbooks must include predefined steps to rapidly identify, contain, and disconnect compromised third-party applications from internal systems.

Related Posts:

AHOY and Lumina Partners Forge Strategic Alliance to Deploy Sovereign Physical AI Across Critical Sectors

Kaspersky unveils how the worst cyber incidents hit SMBs over the past year

Turkish Airlines Named Liverpool FC Main Partner from 2027/28 Season

The Investor 2026 to Tackle Egypt’s Industry and Real Estate Challenges

Tanmeyah Receives Gold Client Protection Certification from MicroFinanza Rating

Bloom Holding Launches Alhambra, the Vibrant Heart and Final Release of Bloom Living

GovAcademy’s Executive Director joins the summit’s opening sessions as Abu Dhabi’s approach to skills intelligence takes centre stage

Zerosploit MEA and Comforte Announce Strategic Data Security Partnership

آخر الأخبار
النيل للطيران تعلن خطة لمضاعفة أسطولها وتتوسع في أسواق جديدة بمعرض العلمين 2026 "Cairo ICT" و"Forbes Middle East" يوقّعان اتفاقية تعاون استراتيجية لرعاية الدورة الثلاثين وزير الشباب والرياضة يشهد المؤتمر الصحفي لبطولة مصر الدولية للفروسية لقفز الحواجز في سوما باي محمد جميل ينضم إلى بنك التعمير والإسكان نائبًا للرئيس التنفيذي والعضو المنتدب المسلماني يهنئ سيف الوزيري ومجلس إدارة المتحدة الجديد ويبحث تعزيز التعاون مع ماسبيرو «مستقبل وطن» يستعين بخبرات الدكتور محمد سناء الدين وافي في أمانة التجارة الداخلية والخارجية السكة الحديد: استعادة حركة القطارات بصورة منتظمة في الاتجاهين على خط القاهرة / أسوان والعكس مصر للطيران للخدمات الأرضية تعزز توسعها بعقد جديد مع Global Aviation Services مصر للطيران للصيانة و"FTAI Aviation" توقعان شراكة استراتيجية خلال معرض العلمين الدولي للطيران2026 مصر للطيران ومطار مارسيليا يناقشان إمكانية تشغيل خط مباشر بين القاهرة ومارسيليا - بفرنسا "السعودي الألماني الصحية" تحصد جائزة "الابتكار في الرعاية الصحية الحكيمة" ضمن "أداء الصحة 2026" الموافقة بالإجماع على سلامة منهجية وأسلوب إعداد الدراسة المحدثة للقيمة العادلة لأسهم بنك القاهرة الأعلى للإعلام: منع ظهور الكابتن أحمد بلال على الوسائل الإعلامية لمدة ٣ أسابيع وزير الكهرباء يبحث مع نظيره السوداني تعزيز التعاون لإعادة تأهيل الشبكات وتوفير الطاقة مصر تدين التوغلات الإسرائيلية المتكررة داخل الأراضى السورية اقتصادية قناة السويس تبحث مع سفير سنغافورة فرصًا جديدة للاستثمار في المشروعات الصناعية واللوجستية شركة هيونداي موتور تصبح الشريك الرسمي للسيارات في دوري أبطال أوروبا شراكة مصرفية جديدة بين بنك التنمية الصناعية IDB وصندوق التنمية الحضرية لتوسيع فرص التملك ودعم التنمي... "إم جي" تتصدر تراخيص السيارات الملاكي في مصر للشهر الثاني على التوالي بإجمالي 2,326 سيارة قمم البحر الأسود في تركيا تحتضن النسخة الثانية من سباق كاتشكار الدولي للركض الجبلي 2026