Kaspersky Reports Chinese Hackers Backdoored Daemon Tools in Widespread Supply-Chain Attack
Kaspersky reported on May 5 that the official
The selectivity between thousands of exposed Windows machines and roughly a dozen follow-on deployments identifies this as a targeted espionage operation, with secondary malware deployed only against government, scientific, and manufacturing systems in Russia, Belarus, and Thailand, consistent with Chinese state intelligence collection priorities. The April 8 detection-to-May 5 disclosure gap indicates secondary exploitation was already underway before public reporting forced remediation. Chinese-language artifacts, attributed solely by Kaspersky's malware analysis without a named APT designation or external government confirmation, may instead reflect deliberate false-flag tradecraft by non-Chinese clusters with both the capability and interest in implicating Beijing. Additional compromises from the same cluster are
4 sources
- Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in widespread attack -
TechCrunch - Popular DAEMON Tools software compromised -
Kaspersky Securelist - Kaspersky identifies ongoing supply chain attack on official Daemon Tools website distributing backdoor malware
- DAEMON Tools trojanized in supply-chain attack to deploy backdoor -
BleepingComputer