Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

Daemon Tools: Supply Chain Attack Compromises Downloads Since April

Kaspersky discovers trojanised installers of the popular Daemon Tools software. Downloads since 8 April are affected - the vendor has not yet responded.

What happened? - Key facts about the supply chain attack

The popular software Daemon Tools Lite has been affected by a serious supply chain attack since 8 April 2024. Anyone who downloaded the software from the official vendor website since that date unknowingly brought malware onto their machine. Kaspersky's virus analysts discovered the compromise and are warning about the infected downloads.

Particularly problematic: the trojanised installers are signed with the vendor's official digital certificates and therefore appear entirely trustworthy at first glance. At the time of the report, the downloads on the official website were still infected, as the vendor AVB Disc Soft had not responded to Kaspersky's attempts to make contact.

The details - Scale and analysis of the compromise

Kaspersky researchers came across the infected installers at the beginning of May and were subsequently able to trace the compromise back to 8 April. The affected installer versions of Daemon Tools and Daemon Tools Lite range from 12.5.0.2421 to 12.5.0.2434.

An analysis of version 12.5.0.233b of the Lite installer on the VirusTotal platform confirms the malware infection with a heuristic detection by Kaspersky (HEUR:Trojan.Win64.Agent.gen). This underlines the authenticity of the warning about the currently available downloads.

Global impact with targeted follow-up payloads

Telemetry from Kaspersky sensors shows the worldwide scale of the attack: individuals and organisations from more than 100 countries have installed the infected software. Daemon Tools is mainly used for working with disk images such as ISO files and is correspondingly widespread.

Of particular note, however, is that of all affected systems only about a dozen downloaded further malware stages. These targeted follow-up payloads affected organisations in retail, academia, government and manufacturing. The affected victims come from Russia, Brazil, Turkey, Spain, Germany, France, Italy and China - a clear indication of targeted attacks on specific objectives.

Context - The growing threat from supply chain attacks

The Daemon Tools incident is part of a worrying series of supply chain attacks. Based on the malware analysis, Kaspersky researchers assess the attackers as Chinese-speaking, which points to professional and state-backed actors.

Supply chain attacks have increased significantly in recent times. At the end of 2023 the popular text editor Notepad++ was already affected, and in mid-April 2024 the CPUID website, home of the popular tools CPU-Z and HWMonitor, also distributed malware via compromised downloads.

How the malware works

The malware injected into Daemon Tools collects extensive system information, including hardware data such as MAC addresses, information about running processes and installed software. It also brings a minimalist backdoor that can download further malicious code.

This functionality makes the malware an ideal tool for espionage and follow-up attacks. The fact that further malware was only downloaded on selected targets underlines the targeted nature of the attack.

Practical tips - Protective measures and response

Organisations and private users should immediately check whether they have downloaded Daemon Tools or Daemon Tools Lite since 8 April 2024. Affected systems should be regarded as compromised and appropriate security measures initiated.

For the future, a multi-layered security strategy is advisable:

  • Regular checking of downloads with up-to-date antivirus software
  • Monitoring of system changes after software installations
  • Implementation of endpoint detection and response (EDR) systems
  • Regular security audits of the IT infrastructure

In its detailed analysis, Kaspersky provides an extensive list of indicators of compromise (IOC) that IT security teams can use to check their systems.

Outlook - Challenges for IT security

The Daemon Tools incident illustrates the growing sophistication of supply chain attacks. The use of official digital certificates and the targeted delivery of malware only to selected victims show how refined modern cyberattacks have become.

For companies it is becoming increasingly important not only to secure their own IT infrastructure but also to monitor the chain of trust of their software suppliers. This requires new approaches in cybersecurity strategy and closer cooperation between vendors and security researchers.

The fact that the vendor AVB Disc Soft has so far not responded to the warnings underlines the need for better communication channels and response processes in the industry. Until the vendor has cleaned up the issue, users should refrain from downloading the affected software and use alternative solutions for working with disk images.