Daemon Tools download distributed with malware included
Users who installed Daemon Tools Lite 12.5.1 (free version) since April 8 are strongly advised to act.
In a plot twist nobody asked for, the latest versions of Daemon Tools Lite apparently decided that mounting ISO files alone was no longer exciting enough. Instead, the software started generously bundling a Trojan horse that quietly opens a backdoor on users’ systems during installation. Because why stop at virtual drives when you can also drive users straight into cybersecurity nightmares?
According to security researchers at Kaspersky, the malware campaign has been active since April 8. Even more impressively, the infected installers were reportedly distributed through the official website, proving once again that sometimes the call really is coming from inside the house.
The compromised version, ranging from 12.5.0.2421 to 12.5.0.2434, contain infected binaries with names that sound perfectly innocent, such as:
- DTHelper.exe
- DiscSoftBusServiceLite.exe
- DTShellHlp.exe
Because nothing says trustworthy utility software quite like a helper executable secretly summoning malware from the internet.
Researchers say the Trojan establishes a backdoor and then downloads additional malicious payloads, turning affected PCs into unwilling participants in the cybercrime starter pack. Thousands of systems across more than 100 countries are believed to have been infected.
Disc Soft, the company behind Daemon Tools, says it has now secured its infrastructure, although it still has not revealed who breached the systems or exactly how attackers got in.
"Following an internal investigation, we identified unauthorized interference within our infrastructure. As a result, certain installation packages were impacted within our build environment and were released in a compromised state. Version 12.6 of DAEMON Tools Lite, which does not contain the suspected compromised files, was released on May 5." the company said.
Users who installed Daemon Tools Lite 12.5.1 (free version) since April 8 are strongly advised to:
- Uninstall the software,
- Run a full antivirus scan,
- Install the clean 12.6 release
The trojanized versions have since been removed, and visitors are now greeted with a warning urging them to upgrade.