Malicious installer distributed on DAEMON Tools official website... undetected for a month

TL;DR AI
2 min readKey summary
Kaspersky says the official Daemon Tools site hosted trojanized installers for versions 12.5.0.2421 to 12.5.0.2434 in a supply-chain attack.
The infected downloads spread to systems in more than 100 countries, with most victims hit by an info-stealer.
A smaller group was manually targeted with shellcode injectors and unknown RATs/backdoors, suggesting more tailored intrusion attempts.
The case shows how trusted vendor websites can bypass normal defenses and quietly expose users and organizations to theft and persistent compromise.



