DAEMON Tools trojanized in supply-chain attack to deploy backdoor
2026-05-05T19:23:35Z•493889d58d4ca5a559b760a06ddbe89ecc7e30c66a9225ca09ad224228578f28
amazon-ses-phishingandroid-malwareapt37auth-bypassbackdoorcloudzcredential-theftcve-2026-22679data-breachftc-enforcementlocation-datamoveit-automationotp-theftpypi-malwarerailway-safetysupply-chain-attacktrojanweaver-e-cology
What happened
A batch of security reports: DAEMON Tools installers were trojanized in a supply‑chain attack that delivered a backdoor to thousands of systems. A critical Weaver E‑cology vulnerability (CVE-2026-22679) has been exploited in the wild since mid‑March. Progress warned of a critical authentication‑bypass in MOVEit Automation. Malicious packages were published to PyPI (backdoored PyTorch Lightning) and a game platform was used to push BirdCall Android malware (APT37). CloudZ RAT added a plugin abusing Microsoft Phone Link to steal SMS/OTPs. Amazon SES is increasingly abused for phishing, and the V
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 493889d58d4ca5a559b760a06ddbe89ecc7e30c66a9225ca09ad224228578f28
- Enrichment time
- 2026-05-05T19:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.