Kasperky warns the popular Daemon Tools app of backdoors by hackers to target specific victims


  • Attackers poisoned DAEMON Tools downloads with malware, infecting thousands worldwide
  • The campaign first deployed an infostealer, followed by a selective backdoor on targeted machines
  • Researchers suspect Chinese actors and note the precision of the attack against government and industrial systems

DAEMON Tools, a popular program used to create and use virtual drives on a computer, was poisoned to deliver dangerous backdoor to thousands of users, experts have warned.

Security researchers Kaspersky published a new report outlining how someone broke into the site with DAEMON Tools around April 8, 2026. They added several new versions of the software, 12.5.0.2421 to 12.5.0.2434 – to DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShelliesHlp.exe

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top