Malicious Backdoor Found in DAEMON Tools Installer

In the DAEMON Tools installer, Kaspersky GReAT specialists discovered a backdoor leading to malicious activity in software builds from version 12.5.0.2421 onwards.

Malicious Backdoor Found in DAEMON Tools Installer

The backdoor has resulted in over 2000 infections across 100+ countries, including Russia. Once installed, the software establishes a connection to a control server, enabling the execution of malicious modules, primarily a data-stealing component. Additionally, a simplified backdoor is sometimes activated to carry out commands and download files.

To address this issue, Kaspersky recommends uninstalling the program and performing a thorough security check on all devices. Organizations are advised to isolate affected systems and reinforce security measures through enhanced audits.