Hackers used Daemon Tools' own website to silently install backdoors on thousands of PCs for nearly a month

TL;DR AI
2 min readKey summary
Researchers found trojanized Daemon Tools Windows installers on the official site from April 8 to early May.
The compromised signed installers embedded a backdoor that collected system information and reached out to attacker infrastructure.
The campaign hit victims in more than 100 countries, with a small number receiving second-stage payloads.
Kaspersky detected the issue and notified vendor AVB Disc Soft after uncovering the compromise.



