INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Malware Was Discovered in Daemon Tools Software

| 2026-05-07 09:30 MEDIUM HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
The supply chain attack on Daemon Tools software has been contained, but not before it infected thousands of machines across more than 100 countries. The incident began when threat actors exploited a vulnerability in the application's installer to hide malware, which was then distributed from the main website. As a result, victims were left vulnerable to various types of cyber attacks, including Trojanized versions of popular software and malicious payloads injected into system processes like [IOC HIDDEN • LOGIN REQUIRED] and [IOC HIDDEN • LOGIN REQUIRED]. The attack highlights the importance of vigilance when installing new software and the need for organizations to carefully examine machines that had Daemon Tools installed after April 8.
Technical Mitigations AI-generated
• Audited the build and release pipeline to identify and isolate affected systems • Rebuilt and validated installation packages to strengthen internal security controls • Strengthened internal security monitoring systems
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

no•••••.exe
co•••••.exe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign EarlierCampaign Earlier
Target & Sectors
DACH DACH manufacturingmanufacturing technologytechnology
Incident Timeline
‎April 8
China-Linked Backdoor Campaign warned users that Daemon Tools software installers distributed from the main website had been Trojanized.
source_region China
campaign Campaign Earlier
organisation China-Linked Backdoor Campaign
organisation Kaspersky
‎May 5
The Daemon Tools Lite software version 12.6 was released by Disc Soft less than 12 hours after being notified of a supply chain attack.
infrastructure 12.6
general_metric 12.6 Version
general_metric 12 hours
‎May 7
Threat actors used Daemon Tools to target their internal infrastructure.
‎2026/05/07
Threat actors used Daemon Tools to infect victims across multiple countries, including Russia, Brazil, and Turkey.
infrastructure 12.5.1
infrastructure 12.6.0
Tactical Metrics
Metrics
infrastructure
‎12.6
Software Version
Metrics
infrastructure
‎12.5.1
Software Version
Metrics
infrastructure
‎12.6.0
Software Version
Intelligence Sources
Infosecurity-Magazine 2026-05-07
Infosecurity-Magazine 2026-05-07