Briefing

DAEMON Tools Supply‑Chain Breach: Trojans in Free Lite Version

security
by Sergiu Gatlan ·

Patch all installations of DAEMON Tools Lite 12.5.1 by uninstalling, scanning, and installing 12.6.0.2445 from the official site.

What to do now

Patch all users of DAEMON Tools Lite 12.5.1 by uninstalling, running a full system scan, and installing the latest 12.6.0.2445 version from the official website.

Summary

On May 6, 2026 Disc Soft confirmed that the free DAEMON Tools Lite had been trojanized in a supply‑chain attack. The malicious installers, ranging from 12.5.0.2421 to 12.5.0.2434, were distributed through the official website and infected over 100 countries. Kaspersky’s analysis shows the payload first stole system data and then deployed a lightweight backdoor, with some victims receiving a QUIC RAT variant. Disc Soft isolated the issue to the free Lite version; paid editions (Pro, Ultra, and paid Lite) were unaffected. Within 12 hours the vendor released a clean version, 12.6.0.2445, on May 5, and removed the compromised binaries. Users who installed 12.5.1 (free) since April 8 are advised to uninstall, run a full system scan, and install the new 12.6.0.2445 build. The company has secured its build environment and is investigating the threat actor and attack vector.

Key changes

  • Trojanized installers 12.5.0.2421‑12.5.0.2434 targeted free Lite only
  • Kaspersky found first‑stage info stealer then lightweight backdoor, some with QUIC RAT
  • Version 12.6.0.2445 released May 5, no malicious behavior
  • Disc Soft secured build environment and removed compromised binaries
  • Users of 12.5.1 advised to uninstall, run full scan, install 12.6.0.2445

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting