# Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in widespread attack

_Thursday, June 25, 2026 at 11:42 PM EDT · Cybersecurity · Latest · Tier 2 — Notable_

![Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in widespread attack — Primary](https://techcrunch.com/wp-content/uploads/2025/01/GettyImages-591881449.jpg?resize=1200,799)

Security researchers at Kaspersky have identified a malicious backdoor planted in Daemon Tools, the popular Windows disc imaging software. The Russian cybersecurity company said data collected from computers running its antivirus software shows a widespread attack targeting thousands of Windows computers running Daemon Tools. Kaspersky linked the hackers to a Chinese-language speaking group based on analysis of the malware.

The backdoor was used to plant additional malware on a dozen computers across the retail, scientific and manufacturing sectors as well as government systems. The targeted organizations are located in Russia, Belarus and Thailand. Kaspersky said the backdoor was first detected on April 8.

The company said it had contacted Disc Soft, the company that maintains Daemon Tools, but did not say if the developer responded or took action. Kaspersky said the supply chain attack is still active. This is the latest in a string of supply chain attacks that have targeted developers of popular software in recent months.

Earlier this year hackers associated with the Chinese government hijacked Notepad++ to deliver malware to organizations with interests in East Asia. Security researchers also warned of another attack last month targeting users who visited the website of CPUID, which makes the popular HWMonitor and CPU-Z tools. TechCrunch downloaded the Windows installer from the Daemon Tools website and the file appeared to contain the backdoor when checked with VirusTotal.

It is not known if the macOS version of Daemon Tools was compromised or if other apps made by Disc Soft are affected. When contacted for comment a Disc Soft representative said they are aware of the report and are currently investigating the situation. The representative said the team is treating this matter with the highest priority and is actively working to assess and address the issue while taking all necessary steps to remediate any potential risks and ensure the security of users.

## Sources

- [TechCrunch](https://techcrunch.com/2026/05/05/kaspersky-suspects-chinese-hackers-planted-a-backdoor-into-daemon-tools-in-widespread-attack/)

---
Canonical: https://techandbusiness.org/newswire/WMYow9Ig064KslncDKjDWi
Retrieved: 2026-06-26T07:58:30.118Z
Publisher: Tech & Business (techandbusiness.org)
