Observed Signal · May 5, 2026 · Supply Chain Attack · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
Kaspersky: Backdoor in Daemon Tools Used in Widespread Attack
Kaspersky researchers reported a malicious backdoor planted in the Windows disc-imaging software Daemon Tools, describing the incident as a "widespread" supply-chain attack affecting thousands of Windows computers. Kaspersky says the backdoor was first detected on April 8 and that telemetry shows thousands of infection attempts and at least a dozen successful intrusions where additional malware was deployed on systems in the retail, scientific, manufacturing and government sectors. The targeted organizations are located in Russia, Belarus and Thailand. Kaspersky linked the campaign to a Chinese-language speaking threat actor based on malware analysis. TechCrunch verified a compromised Daemon Tools installer on the vendor website via VirusTotal. Disc Soft (the Daemon Tools maintainer) said it is investigating.
Active supply-chain compromise of widely used Windows software with thousands of infection attempts and confirmed successful intrusions — underscores growing risk from software-update based attacks and has cross-sector implications for software integrity and organizational security.
Track Real-Time Supply Chain Attack Signals & Market Shifts
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Kaspersky detected a malicious backdoor in Daemon Tools and called the campaign a "widespread" supply-chain attack.
- Kaspersky reports the backdoor was first detected on 2026-04-08 and that telemetry shows thousands of infection attempts and at least a dozen successful compromises.
- Affected sectors include retail, scientific, manufacturing and government; targeted organizations were observed in Russia, Belarus and Thailand.
- Kaspersky linked the campaign to a Chinese-language speaking hacker group based on malware analysis.
- TechCrunch checked the Daemon Tools Windows installer and found the file flagged by VirusTotal; Disc Soft said it is investigating.
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Rival hackers evict TeamPCP, deploy worm 'PCPJack'
An unknown hacking group, tracked by SentinelOne as “PCPJack,” has been compromising systems previously breached by the cybercrime group TeamPCP. According to a SentinelOne report, the attackers break into TeamPCP‑compromised environments, remove TeamPCP’s tooling, evict its operators, then deploy self‑propagating code that steals credentials and exfiltrates data. The group appears focused on cloud infrastructure and also scans the public internet for exposed services such as Docker and MongoDB. SentinelOne researcher Alex Delamotte said the motives appear financial — stolen credentials are monetized via resale, initial‑access brokering, or direct extortion — and proposed theories including disgruntled ex‑TeamPCP members, rival operators, or imitators modeling TeamPCP’s tools. The campaign is notable for targeting previously compromised environments and using phishing domains (including password‑manager themed sites) and fake help‑desk pages as part of its activity.
Microsoft and BKA Disable 200 Hacker Servers Worldwide
Microsoft, Europol and the German Bundeskriminalamt (BKA) carried out an international operation that disabled more than 200 command-and-control servers and severed criminal control over over 18,000 identified victim computers. The takedown targeted two widely used malware families, Amadey and StealC. Investigators used artificial intelligence to accelerate reverse-engineering of complex code and Microsoft's legal team invoked the U.S. RICO statute to treat multiple actors as a single conspiracy, enabling a coordinated, large-scale attack on the shared infrastructure. German authorities and Europol’s EC3 participated in the effort, which builds on previous international actions such as Operation Endgame from May 2024.
AI-Agent 'Jadepuffer' Runs Adaptive Ransomware
Security researchers at Sysdig uncovered a novel ransomware attacker dubbed “Jadepuffer” that appears to be controlled by an AI agent. The agent used natural-language-driven code and rapid iterative problem-solving — in one case completing an adaptation in 31 seconds — to place ransomware. It exploited a vulnerability in the open-source Langflow framework to harvest unencrypted cloud credentials and API keys, which enabled lateral movement and persistent tasks. Jadepuffer targeted MySQL servers running the Alibaba Nacos configuration service, creating admin accounts and encrypting 1,342 configuration files before deleting originals. The attacker generated a ransom table with a Bitcoin wallet and Proton‑Mail contact; analysts report the wallet moved roughly 46 BTC across about 73 transactions. Researchers warn AI agents lower the skill barrier for automated, adaptive cyberattacks against unpatched systems.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
