Introduction to Supply-Chain Attacks
The DAEMON Tools disk app has been backdoored in a month-long supply-chain attack. This type of attack involves compromising a software supply chain, allowing attackers to gain access to multiple organizations through a single vulnerability. The DAEMON Tools attack is just one of several recent supply-chain attacks, including those targeting Trivy, Checkmarx, and Bitwarden.
Impact of the Attack
The attack on DAEMON Tools affected around 100 organizations, primarily located in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. The attackers used a minimalistic backdoor to execute commands, download files, and run shellcode payloads in memory. A more complex backdoor, dubbed QUIC RAT, was also installed on a single machine belonging to an educational institution in Russia. This backdoor can inject payloads into system processes and supports various communication protocols.
Source
Original reporting by Ars Technica.