DAEMON Tools distributed infected installers from its own site
DAEMON Tools has confirmed a supply chain compromise in which trojanised installers were distributed through the vendor's own official website between April and May 2026, enabling remote command execution and persistent backdoor access on infected systems. Kaspersky's analysis indicates the operation was not purely opportunistic: only a small subset of victims received second-stage payloads, suggesting victims were profiled and selectively targeted before the full backdoor was deployed.
What this means for your organisation
The fact that the software came from the vendor's own site is exactly the problem. Advice to download software only from official sources does not help when the source itself is compromised. Tools of this kind are often installed by individual users without going through IT, leaving you with neither an overview of who has them nor a way to remove them centrally. That the attackers selected their victims suggests some were chosen because they were of interest.
Berigo recommends
- Determine whether DAEMON Tools is present on any machines in your estate, and remove affected versions.
- Investigate activity going back to 8 April on machines where the software has been installed.
- Treat confirmed infections as full compromises, and change passwords and tokens the user held on those machines.
- Limit end users' ability to install software themselves, and then work on gaining visibility of what is already installed.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch