Skip to content
Supply chainContained

DAEMON Tools official installers trojanized in month-long supply-chain attack

Kaspersky revealed that signed installers downloaded from the official DAEMON Tools website had carried a backdoor since 8 April 2026, infecting thousands of machines in more than 100 countries and delivering follow-on implants, including QUIC RAT, to about a dozen selected targets.

Victim
DAEMON Tools (AVB Disc Soft) users

On 5 May 2026, Kaspersky disclosed that installers for DAEMON Tools, the long-running Windows disc-imaging utility, had been trojanized at the source. Since 8 April 2026, copies downloaded from the legitimate DAEMON Tools website carried malicious code, and the files were signed with valid AVB Disc Soft certificates, so they looked legitimate to users and to many security controls.

How the attack worked

Versions 12.5.0.2421 through 12.5.0.2434 of the Windows edition were affected. The attackers injected code into three legitimate binaries shipped with the product (DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe), which are set to run at Windows startup.

The first stage profiled each infected machine, collecting the hostname, MAC address, running processes, installed software and locale. Based on that profile, the operators chose which victims received a lightweight backdoor able to run commands and fetch more payloads. In at least one case they deployed QUIC RAT, a more capable implant that supports several protocols and process injection.

Scale and targets

The compromised installers led to thousands of infections in more than 100 countries, but second-stage payloads reached only about a dozen machines, belonging to retail, scientific, government and manufacturing organizations in Russia, Belarus and Thailand. That pattern points to a broad net cast to find a small number of high-value targets. Kaspersky described the operator as Chinese-speaking, based on strings in the malware, without attributing it to a known group.

The vendor later released version 12.6.0.2445, which no longer contains the malicious code.

Why it matters

The attack is a textbook software supply-chain compromise: users who did everything right, downloading from the official site and receiving a properly signed binary, were still infected. A valid code signature shows who built a file, not whether the build pipeline was compromised.

Timeline

  1. Trojanized DAEMON Tools installers, signed with valid AVB Disc Soft certificates, begin to be distributed from the official website.

  2. Kaspersky publicly discloses the supply-chain compromise affecting versions 12.5.0.2421 to 12.5.0.2434.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/
  2. thehackernews.comhttps://thehackernews.com/2026/05/daemon-tools-supply-chain-attack.html
  3. helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/05/06/daemon-tools-compromised-backdoors-supply-chain-attack/

Related incidents

Supply chainContained

SolarWinds SUNBURST supply-chain compromise (Cozy Bear)

Russian SVR operators trojanized SolarWinds Orion build infrastructure, distributing a backdoored update to 18,000 customers including the U.S. Treasury, Commerce, DHS, State, and Energy departments. The defining state cyberespionage operation of the decade.

Victim
SolarWinds (Orion customers โ€” ~18,000 organisations including 9 U.S. federal agencies and Microsoft, FireEye, Mimecast)
Loss
$100.00B