1 min readfrom TechCrunch

Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in ‘widespread’ attack

Our take

Kaspersky has raised alarms over a significant cybersecurity threat, suspecting that Chinese hackers have implanted a backdoor into Daemon Tools, a widely used software for Windows. The cybersecurity firm reports thousands of attempts to exploit this vulnerability, with at least a dozen confirmed successful infiltrations following the installation of malicious versions of the program.
Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in ‘widespread’ attack

The revelation that suspected Chinese hackers embedded a backdoor into Daemon Tools, a widely used Windows disk imaging utility, serves as another stark reminder that supply chain attacks have moved from theoretical threat to operational reality. Kaspersky's detection of thousands of infection attempts and at least a dozen confirmed breaches underscores a troubling pattern: attackers are increasingly targeting trusted software distribution channels rather than attempting to breach individual endpoints directly. This shift demands that both security professionals and everyday users recalibrate their understanding of what it means to practice good digital hygiene.

What makes this incident particularly concerning is the choice of target. Daemon Tools occupies a specific niche as legitimate software that millions of users have downloaded over the years for creating virtual drives and mounting disk images. By compromising such a utility, attackers exploit the fundamental trust users place in familiar tools. The cybersecurity community has long warned about the dangers of software supply chains, but each successful attack reinforces the uncomfortable truth that even cautious users who stick to well-known applications can find themselves compromised. This creates a psychological burden that security practitioners must acknowledge when communicating risk to non-technical audiences.

The technical sophistication behind this operation raises questions about the resources and patience of the attackers. Supply chain compromises require significant planning, often involving months of preparation before any malicious activity becomes visible. The fact that Kaspersky has identified thousands of attempted infections suggests this campaign was designed for scale, potentially serving purposes ranging from intelligence gathering to establishing persistent access across multiple organizations. For readers exploring how AI systems might

The cybersecurity company says it's seen thousands of infection attempts, and at least a dozen successful hacks after users installed malicious versions of the popular Windows software.

Read on the original site

Open the publisher's page for the full experience

View original article