Disc Soft Limited Issues Malware‑Free DAEMON Tools Version After Supply‑Chain Breach
Remove the trojanized DAEMON Tools installers and run a full malware scan to eliminate the embedded backdoor.
Remove the trojanized DAEMON Tools installers, run a full malware scan, and audit for persistence backdoors on affected systems.
Summary
Disc Soft Limited, the developer of the popular DAEMON Tools Lite utility, confirmed that its free version had been compromised in a supply‑chain attack that distributed trojan‑laden installers through the company’s official website. The malicious binaries, numbered 12.5.0.2421 to 12.5.0.2434, were released between early April and early May 2026 and infected thousands of users worldwide, including those in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. Kaspersky researchers identified a basic information‑stealing component that harvested system data, as well as a lightweight backdoor capable of executing commands, downloading files, and running code directly in memory. A subset of victims also received a QUIC RAT variant, adding further remote‑control capabilities.
In response, Disc Soft promptly released a clean, malware‑free build—version 12.6—on May 5, 2026. The company clarified that the paid Pro and Ultra editions remained unaffected and that the breach was confined to the free Lite edition. Users who installed any 12.5.1 build since April 8 are urged to uninstall the compromised software, perform a full system scan, and install the latest 12.6 release from the official site. To prevent future incidents, Disc Soft has secured its build environment and removed the compromised binaries from distribution, emphasizing the importance of verifying installer integrity and maintaining robust supply‑chain security.
The incident highlights the growing threat of supply‑chain attacks on widely used software and underscores the need for both developers and users to adopt stringent security practices. By promptly addressing the breach and issuing a clean update, Disc Soft demonstrated a commitment to protecting its user base, while the broader cybersecurity community is reminded that even popular, free utilities can become vectors for sophisticated malware.
Key changes
- Trojanized installers for DAEMON Tools versions 12.5.0.2421‑12.5.0.2434 delivered a backdoor from Apr 8, 2026.
- Compromised binaries DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe embed a first‑stage info‑stealer and a second‑stage backdoor.
- The backdoor can execute commands, download payloads, and run code directly in memory; QUIC RAT used in a Russian educational institute case.
- Attack targeted high‑value organizations in Russia, Belarus, and Thailand, and evaded detection for ~1 month.
- Kaspersky attributes the threat to a Chinese‑speaking actor based on payload strings.
- The supply‑chain compromise exploited digitally signed installers, underscoring the need for rigorous integrity checks.
- Similar supply‑chain attacks have been detected almost every month of 2026, indicating a persistent threat landscape.
- The compromised installers are still distributed via the official DAEMON Tools website.