Kaspersky Finds Supply‑Chain Attack on DAEMON Tools Installers
Patch: Verify installer signatures and update to the latest DAEMON Tools version to mitigate the supply chain attack.
Patch: Verify installer signatures and update to the latest DAEMON Tools version to mitigate the supply chain attack.
Summary
Kaspersky researchers have uncovered a new supply‑chain attack that targets the installers of DAEMON Tools, a popular disk‑image utility. The attackers have compromised the installers that are distributed from the legitimate DAEMON Tools website, embedding a malicious payload that is executed when the software is installed. Despite the installers being signed with digital certificates belonging to DAEMON Tools developers, the signatures have been forged or the certificates have been compromised, allowing the malicious code to pass initial verification checks. The attack was identified by Kaspersky researchers Igor Kuznetsov, Georgy Kucherin, and Leonid, who noted that the compromised installers are still being served from the official site.
The malicious payload is designed to install additional malware on the victim’s system, potentially giving attackers remote access or persistence. No official patch or update from DAEMON Tools has been announced yet, but users are advised to verify the integrity of any installer they download and to keep their software up to date. The incident highlights the growing risk of supply‑chain attacks even on well‑known software vendors.
Key changes
- Supply‑chain attack discovered targeting DAEMON Tools installers
- Compromised installers are distributed from the legitimate DAEMON Tools website
- Installers are signed with DAEMON Tools developers' digital certificates, yet contain malicious payloads
- Kaspersky researchers Igor Kuznetsov, Georgy Kucherin, and Leonid identified the attack
- The malicious payload installs additional malware, potentially enabling remote access
- No official patch has been released; users should verify installer signatures and keep software up to date