- The attack dynamics: how a backdoor enters a company
- Who is behind it: the Chinese hacker hypothesis
- Immediate impact on Italian SMEs with Windows machine fleets
- What to do now: priority actions in the next 48 hours
- The work still in progress: supply chain security as a structural priority
- Outlook: what awaits us in the coming months
Kaspersky has spotted a large-scale malicious campaign. Hackers allegedly of Chinese origin have inserted a backdoor into fake versions of Daemon Tools, the popular Windows software for managing disk images. Plus, researchers have already logged at least a dozen confirmed compromises and thousands of infection attempts.
Therefore, any organization using Daemon Tools on Windows business machines must consider itself potentially exposed. In particular, Italian SMEs — often lacking dedicated security measures — represent a high-risk target. Consequently, the immediate priority is to verify the origin of installations present in the company and isolate suspicious systems.
We at SHM Studio we constantly monitor the digital threat landscape to support client SMEs in managing cyber risk. In short: this incident confirms that the software supply chain — even for seemingly harmless tools — is now a primary attack vector. Acting promptly is essential.
The attack dynamics: how a backdoor enters a company
On May 5, 2026, Kaspersky researchers published a technical analysis that immediately caught the attention of the cybersecurity community. According to reports by TechCrunch , the attack vector is Daemon Tools, software widely used in the Windows environment for managing disk images in ISO format and similar.
Specifically, attackers reportedly distributed modified versions of the program through unofficial channels. Users who downloaded and installed these versions unknowingly opened a remote access door to their systems. Therefore, the damage is not related to a vulnerability in the original software, but rather to the replacement of the installer with a compromised copy.
Kaspersky estimates thousands of infection attempts and at least twelve confirmed compromises. However, the actual number could be significantly higher, considering that many SMEs lack advanced detection tools.
Who is behind it: the Chinese hacker hypothesis
Kaspersky researchers link the operation to a threat group allegedly connected to China. However, attribution in cybersecurity is always a complex task. In fact, technical indicators—including command-and-control infrastructure and obfuscation techniques—are consistent with campaigns previously documented by other security vendors.
According to Gartner Cybersecurity Insights , software supply chain attacks are constantly growing. Consequently, it is not surprising that popular software like Daemon Tools has become a strategic vector. Similarly, similar incidents have previously involved tools like CCleaner and SolarWinds.
Beyond this, the choice of Daemon Tools is no coincidence. The software is particularly widespread in small-to-medium business contexts, which often lack strict policies on installation management. Therefore, the profile of potential victims matches exactly that of Italian SMEs.
Immediate impact on Italian SMEs with Windows machine fleets
Italian small and medium-sized enterprises represent a significant share of Windows users in Europe. In many cases, internal IT departments are small or non-existent. For this reason, software management often happens informally, with downloads from unverified sources.
Therefore, the concrete risk for an SME is twofold. First of all, there is the risk of sensitive data exfiltration — credentials, customer data, financial information — through the installed backdoor. Subsequently, once an endpoint is compromised, the attacker can move laterally within the corporate network, reaching critical systems.
We at SHM Studio we work daily with SMEs that manage B2B and retail customer data. Therefore, we understand well how a single compromised endpoint can become the entry point for a much larger breach. The digital strategy a company's cannot ignore a minimum level of cybersecurity.
What to do now: priority actions in the next 48 hours
Faced with an active and documented threat, the response must be swift and methodical. Here are the priority actions that every IT manager or SME owner should initiate immediately.
- Inventory of installations: check all company devices for Daemon Tools. Verify the installed version and the hash of the executable file against the official ones.
- Preventive isolation: any machine with dubious origin installations must be isolated from the company network until the analysis is complete.
- Scanning with updated tools: perform a full scan with EDR or antivirus solutions updated to the latest definitions. Kaspersky has already released specific signatures for this threat.
- Review of download policies: introduce or strengthen company policies on software installation, limiting downloads to official and verified channels only.
- Notification to the DPO: if the compromised systems process personal data, assess the obligation to notify the Privacy Authority within 72 hours, as required by GDPR.
Furthermore, it is advisable to consult the CISA catalog of actively exploited vulnerabilities for real-time updates on this and other related threats.
The work still in progress: supply chain security as a structural priority
This incident is not an isolated event. Instead, it's part of a growing trend where attackers target the software supply chain rather than the target systems directly. According to recent McKinsey research, organizations that invest in software supply chain controls significantly reduce their exposed attack surface.
However, for many Italian SMEs, supply chain security remains an abstract concept. In fact, daily operational priorities leave little room for strategic security planning. Yet, as the Daemon Tools case shows, even a seemingly trivial utility software can become a critical vector.
For this reason, the consulting in AI and automation that SHM Studio offers to SMEs always includes a comprehensive digital risk assessment. Integrating security into digitalization processes is not an extra cost: it is a necessary condition for business continuity. Similarly, the choice of digital tools — from web systems to marketing platforms — must take security requirements into account from the design phase.
Outlook: what awaits us in the coming months
The campaign documented by Kaspersky may not be over. Therefore, new indicators of compromise and additional victims are likely to emerge in the coming weeks. Furthermore, it is reasonable to expect that other Windows utility software — with a large user base and limited distribution controls — will be targeted with similar techniques.
In this scenario, Italian SMEs operating in B2B and retail must accelerate the transition towards more structured IT management models. This doesn't necessarily mean setting up an internal SOC. Instead, it means adopting minimal digital hygiene practices: centralized update management, privileged access control, periodic staff training.
Finally, who manages digital campaigns — on Google Ads , on Linkedin or through activities of SEO — must consider that a compromised system can invalidate months of work. Analytics data, ad platform credentials, and content from corporate blog are all exposed assets in case of a breach. Therefore, cybersecurity is not exclusively a technical issue: it is a component of digital marketing and online reputation. To learn more or request an assessment, you can contact the SHM Studio team . The strategic copywriting and a company's digital presence are worth as much as the security of the systems that host them.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.