News Grower

Independent coverage of AI, startups, and technology.

Ars Technica May 5, 2026 at 19:46 Big Tech Rising Hot

Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack

Daemon Tools users: It's time to check your machines for stealthy infections, stat.

Signal weather

Rising

Momentum is building quickly, so this card is a good early entry point into the topic.

By Dan Goodin Original source
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack

Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates from the servers of its developer, researchers said Tuesday. Kaspersky, the security firm reporting the supply-chain attack, said it began on April 8 and remained active as of the time its post went live. Installers that are signed by the developer’s official digital certificate and downloaded from its website infect Daemon Tools executables, causing the malware to run at boot time. Kaspersky didn’t explicitly say so, but based on technical details, the infected versions appear to be only those that run on Windows. Versions 12.5.0.2421 through 12.5.0.2434 are affected. Neither Kaspersky nor developer AVB could be contacted immediately for additional details. Hard to defend against Infected versions contain an initial payload that collects MAC addresses, hostnames, DNS domain names, running processes, installed software, and system locales. The malware sends them to an attacker-controlled server. Thousands of machines in more than 100 countries were targeted. Out of the many machines infected, about 12 of them, belonging to retail, scientific, government and manufacturing organizations, have received a follow-on payload—an indication the supply-chain attack targets select groups. Read full article Comments

Stay on the signal

Follow Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

Fresh coverage with immediate momentum.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Ars Technica, Attack Daemon, and Backdoored, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

May 5, 2026 at 19:46 Ars Technica

Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack

Daemon Tools users: It's time to check your machines for stealthy infections, stat.

May 5, 2026 at 17:45 SecurityLab

Недавно устанавливали DAEMON Tools? Похоже, вы приютили шпиона

Скрытый наблюдатель уже вовсю изучает содержимое вашего жёсткого диска.

May 5, 2026 at 17:17 Ars Technica

Google Home gets upgraded Gemini voice assistant and new camera controls

Google's smart home ecosystem is getting its biggest update since the AI-fueled 2025 revamp.

May 5, 2026 at 17:07 Ars Technica

Trump SEC lets Musk settle $150 million Twitter lawsuit for $1.5 million

SEC alleged Musk's late disclosure cheated Twitter investors out of $150 million.

May 5, 2026 at 15:20 TechCrunch

Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in ‘widespread’ attack

The cybersecurity company says it's seen thousands of infection attempts, and at least a dozen successful hacks after users installed mal...

May 5, 2026 at 15:20 Ars Technica

Charlize Theron is a bewitching Circe in Odyssey trailer

"You're a man who needs to control his fate. But you cannot control this."

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

3

Related articles

More stories that share tags, source, or category context.

SecurityLab May 5, 2026 at 17:45 Cybersecurity
Rising Hot

Недавно устанавливали DAEMON Tools? Похоже, вы приютили шпиона

Скрытый наблюдатель уже вовсю изучает содержимое вашего жёсткого диска.

Signal weather

Momentum is building quickly, so this card is a good early entry point into the topic.

Why now

Fresh coverage with immediate momentum.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page