Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack
Daemon Tools users: It's time to check your machines for stealthy infections, stat.
Signal weather
Rising
Momentum is building quickly, so this card is a good early entry point into the topic.
Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates from the servers of its developer, researchers said Tuesday. Kaspersky, the security firm reporting the supply-chain attack, said it began on April 8 and remained active as of the time its post went live. Installers that are signed by the developer’s official digital certificate and downloaded from its website infect Daemon Tools executables, causing the malware to run at boot time. Kaspersky didn’t explicitly say so, but based on technical details, the infected versions appear to be only those that run on Windows. Versions 12.5.0.2421 through 12.5.0.2434 are affected. Neither Kaspersky nor developer AVB could be contacted immediately for additional details. Hard to defend against Infected versions contain an initial payload that collects MAC addresses, hostnames, DNS domain names, running processes, installed software, and system locales. The malware sends them to an attacker-controlled server. Thousands of machines in more than 100 countries were targeted. Out of the many machines infected, about 12 of them, belonging to retail, scientific, government and manufacturing organizations, have received a follow-on payload—an indication the supply-chain attack targets select groups. Read full article Comments
Stay on the signal
Follow Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack
Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.
Story map
Understand this topic fast
A quick entry into the story: why it matters now, who is involved, and where to go next for context.
Why it matters now
Topic constellation
Open the live map for this story
See which entities, story threads, sources, and follow-up articles shape this story right now.
Click nodes to continue
Story timeline
Continue with this story
A short sequence of events and follow-up stories to understand the arc quickly.
How reliable this looks
Signal and trust for Ars Technica
This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.
Reliability
92
Freshness
100
Sources in storyline
3
Related articles
More stories that share tags, source, or category context.
Недавно устанавливали DAEMON Tools? Похоже, вы приютили шпиона
Скрытый наблюдатель уже вовсю изучает содержимое вашего жёсткого диска.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Google Home gets upgraded Gemini voice assistant and new camera controls
Google's smart home ecosystem is getting its biggest update since the AI-fueled 2025 revamp.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Trump SEC lets Musk settle $150 million Twitter lawsuit for $1.5 million
SEC alleged Musk's late disclosure cheated Twitter investors out of $150 million.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Charlize Theron is a bewitching Circe in Odyssey trailer
"You're a man who needs to control his fate. But you cannot control this."
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
RFK Jr. plans to curb antidepressants, which he falsely compares to heroin
Kennedy has made—and continues to make—many false claims about SSRIs.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Google Home gets upgraded Gemini voice assistant and new camera controls
Google's smart home ecosystem is getting its biggest update since the AI-fueled 2025 revamp.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Trump SEC lets Musk settle $150 million Twitter lawsuit for $1.5 million
SEC alleged Musk's late disclosure cheated Twitter investors out of $150 million.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
How do you design a $30,000 electric pickup? Inside Ford's skunkworks.
We tour Ford’s top-secret Electric Vehicle Development Center in California.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.