Adversary Intelligence — 2026-05-05

Kaspersky Reports Chinese Hackers Backdoored Daemon Tools in Widespread Supply-Chain Attack

Kaspersky reported on May 5 that the official Daemon Tools Windows installer has been compromised in an active supply-chain attack, with the backdoor first detected on April 8. The company attributed the operation to a Chinese-language threat actor based on malware analysis, and said telemetry from its global sensor network shows thousands of Windows machines running Daemon Tools have been exposed. Kaspersky additionally identified targeted follow-on malware deployments on roughly a dozen systems across the retail, scientific, manufacturing, and government sectors in Russia, Belarus, and Thailand. TechCrunch independently verified the backdoor by submitting a downloaded installer to VirusTotal; Disc Soft, the software's developer, told TechCrunch it is investigating and treating the matter as "highest priority."

Analysis
The selectivity between thousands of exposed Windows machines and roughly a dozen follow-on deployments identifies this as a targeted espionage operation, with secondary malware deployed only against government, scientific, and manufacturing systems in Russia, Belarus, and Thailand, consistent with Chinese state intelligence collection priorities. The April 8 detection-to-May 5 disclosure gap indicates secondary exploitation was already underway before public reporting forced remediation. Chinese-language artifacts, attributed solely by Kaspersky's malware analysis without a named APT designation or external government confirmation, may instead reflect deliberate false-flag tradecraft by non-Chinese clusters with both the capability and interest in implicating Beijing. Additional compromises from the same cluster are likely to be publicly disclosed within 60 days.
4 sources
  1. Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in widespread attack - TechCrunch
  2. Popular DAEMON Tools software compromised - Kaspersky Securelist
  3. Kaspersky identifies ongoing supply chain attack on official Daemon Tools website distributing backdoor malware
  4. DAEMON Tools trojanized in supply-chain attack to deploy backdoor - BleepingComputer

View in full brief →

UNCLASSIFIED // OPEN SOURCE