Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in ‘widespread’ attack in 2026
Security researchers at Kaspersky say they have identified a malicious backdoor planted in the popular and long-running Windows disc imaging software, Daemon Tools.
The Russian cybersecurity company said on Tuesday that data collected from computers around the world running the Kaspersky antivirus software shows a “widespread” attack is under way, targeting thousands of Windows computers running Daemon Tools.
The hackers, whom Kaspersky has linked to a Chinese-language speaking group based on an analysis of the malware, used the backdoor in Daemon Tools to plant additional malware on a dozen computers across the retail, scientific and manufacturing sectors, as well as government systems. Kaspersky said the hacking of these specific computers implied a “targeted” effort.
The company said the targeted organizations are located in Russia, Belarus, and Thailand.
Table of Contents
Chinese hackers planted a backdoor into Daemon Tools
Kaspersky said the backdoor was first detected on April 8.

Kaspersky said it had contacted Disc Soft, the company that maintains Daemon Tools, but did not say if the developer responded or took action. Kaspersky said the supply chain attack is “still active,” suggesting that the hackers can still plant malware on thousands of computers running the disc imaging software.
This is the latest in a string of so-called “supply chain” attacks that have targeted developers of popular software in recent months. Hackers are increasingly taking aim at the accounts of developers who work on widely used code and software, and abusing that access to push malicious code to anyone who relies on the software. This approach lets the hackers break into a large number of computers at once when their malicious code is delivered as a software update.
Earlier this year, hackers associated with the Chinese government hijacked the popular text editing software Notepad++ to deliver malware to a number of organizations with interests in East Asia. Security researchers also warned of another attack last month targeting users who visited the website of CPUID, which makes the popular HWMonitor and CPU-Z tools.
TechCrunch downloaded the Windows installer from Daemon Tools’ website, and the file appeared to contain the backdoor when we checked it with the online malware scanner service VirusTotal.
It’s not known if the macOS version of Daemon Tools was compromised, or if other apps made by Disc Soft are affected.
When contacted for comment, a Disc Soft representative said they are “aware of the report and are currently investigating the situation.”
“Our team is treating this matter with the highest priority and is actively working to assess and address the issue. At this stage, we are not in a position to confirm specific details referenced in the report. However, we are taking all necessary steps to remediate any potential risks and to ensure the security of our users,” the representative said.
OpenAI hacks Hugging Face
In this incident, OpenAI was running “an internal evaluation” of a model with “maximal cyber capabilities.” The plan was to have it solve a cybersecurity challenge in an environment with no internet access. Instead of solving the challenge, the model found an unknown vulnerability to escape the sandbox and gained internet access. From there, several agents worked together to target and hack Hugging Face thinking they could find the solution to the challenge there. OpenAI only found out after Hugging Face disclosed it had been a victim of a fully autonomous attack. Whoops.
Anthropic discloses it hacked three companies
OpenAI’s disclosure piqued the curiosity of Anthropic, who wondered: Could this have happened to us too? Turns out, the answer was yes. Three times yes. The frontier lab discovered that its own models breached three different and still unnamed companies, with the earlier incident dating back to April — more than three months before the company discovered it. Anthropic partially blamed Irregular, a startup that runs AI cyber evaluations. Whoops.
OpenAI finds out that, actually, Hugging Face wasn’t the only victim
Once OpenAI started investigating the Hugging Face breach, it found out that the agents that hacked Hugging Face also broke into four accounts and four different companies, as Reuters first reported. Modal, an AI inference startup, was one of the victims. Whoops.
Irregular realizes an OpenAI model hacked a company
In late July, Irregular told OpenAI that one of its models that was participating in a Capture-the-Flag competition — essentially a cybersecurity game where players hack systems designed specifically for the competition — escaped the game, connected to the internet, and hacked a real company. The reason? Irregular had given one of the fictional targets the same name of a real company. Whoops.
U.K.’s AI Security Institute tries to hack “real people and organisations”
Also in late July, the U.K. government’s AI Security Institute (AISI), a public body tasked with researching the safety and risks of AI technologies, disclosed that it detected several incidents involving both OpenAI and Anthropic models that while running “routine” evaluations targeted “real people and organisations.” In these cases, AISI had given the models internet access. Whoops. The good news is that the agency actually detected the incidents as they happened, rather than weeks later like in other incidents.
Meta AI hacks a company during testing
In early August, Meta became the last company to disclose an incident involving one of its LLMs, which hacked “a third-party” service. Meta blamed the incident on a misconfiguration by Irregular, which was running a cybersecurity valuation for the tech giant that was supposed to not have internet access. Whoops.
Claude agent hacks gym’s software to book a class
An Australian man asked an Anthropic AI agent to help him book a gym class, which he was on a waiting list for. “I was just sitting on the couch thinking, ‘Gee, this is a chore,’” the man told ABC Australia. In its attempt to comply with the request, the agent found a vulnerability in the gym’s booking software, exploited it, and kicked out people who were ahead of the man on the waitlist. The man tried to undo the damage, asking the agent to undo its actions. The agent replied: “Bad news — I can’t add them back.” Whoops.