Briefing

Disc Soft Limited Issues Malware‑Free DAEMON Tools Version After Supply‑Chain Breach

security
by Bill Toulas ·

Remove the trojanized DAEMON Tools installers and run a full malware scan to eliminate the embedded backdoor.

What to do now

Remove the trojanized DAEMON Tools installers, run a full malware scan, and audit for persistence backdoors on affected systems.

Summary

Disc Soft Limited, the developer of the popular DAEMON Tools Lite utility, confirmed that its free version had been compromised in a supply‑chain attack that distributed trojan‑laden installers through the company’s official website. The malicious binaries, numbered 12.5.0.2421 to 12.5.0.2434, were released between early April and early May 2026 and infected thousands of users worldwide, including those in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. Kaspersky researchers identified a basic information‑stealing component that harvested system data, as well as a lightweight backdoor capable of executing commands, downloading files, and running code directly in memory. A subset of victims also received a QUIC RAT variant, adding further remote‑control capabilities.

In response, Disc Soft promptly released a clean, malware‑free build—version 12.6—on May 5, 2026. The company clarified that the paid Pro and Ultra editions remained unaffected and that the breach was confined to the free Lite edition. Users who installed any 12.5.1 build since April 8 are urged to uninstall the compromised software, perform a full system scan, and install the latest 12.6 release from the official site. To prevent future incidents, Disc Soft has secured its build environment and removed the compromised binaries from distribution, emphasizing the importance of verifying installer integrity and maintaining robust supply‑chain security.

The incident highlights the growing threat of supply‑chain attacks on widely used software and underscores the need for both developers and users to adopt stringent security practices. By promptly addressing the breach and issuing a clean update, Disc Soft demonstrated a commitment to protecting its user base, while the broader cybersecurity community is reminded that even popular, free utilities can become vectors for sophisticated malware.

Key changes

  • Trojanized installers for DAEMON Tools versions 12.5.0.2421‑12.5.0.2434 delivered a backdoor from Apr 8, 2026.
  • Compromised binaries DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe embed a first‑stage info‑stealer and a second‑stage backdoor.
  • The backdoor can execute commands, download payloads, and run code directly in memory; QUIC RAT used in a Russian educational institute case.
  • Attack targeted high‑value organizations in Russia, Belarus, and Thailand, and evaded detection for ~1 month.
  • Kaspersky attributes the threat to a Chinese‑speaking actor based on payload strings.
  • The supply‑chain compromise exploited digitally signed installers, underscoring the need for rigorous integrity checks.
  • Similar supply‑chain attacks have been detected almost every month of 2026, indicating a persistent threat landscape.
  • The compromised installers are still distributed via the official DAEMON Tools website.

Affects

enterprise internal

Source angles · 3 perspectives

Bleeping Computer
Independent angle

DAEMON Tools trojanized in supply-chain attack to deploy backdoor

Open
Bleeping Computer
Independent angle

DAEMON Tools devs confirm breach, release malware‑free version

Open
The Hacker News
Independent angle

DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting