Threat reportMalwareTL-2026-0472

DAEMON Tools Lite Supply-Chain Compromise — Trojanized Signed Installers Deploy Multi-Stage Infostealer + QUIC RAT (Disc Soft, April-May 2026)

criticalMONITORING

DAEMON Tools Lite Supply-Chain Compromise (TL-2026-0472), also tracked as DAEMON Tools Lite Supply-Chain Compromise, is a critical-severity malware campaign, first published 2026-05-07. It carries a reported China nexus and is not formally attributed, affects Disc Soft Limited DAEMON Tools Lite (free edition), maps to 25 MITRE ATT&CK techniques (T1016, T1027, T1036.005), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-0472

Threat ID
TL-2026-0472
Also known as
DAEMON Tools Lite Supply-Chain Compromise, Disc Soft Build Environment Breach (April 2026), DTHelper Trojanization Campaign
Severity
CRITICAL
Status
MONITORING
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
retail, scientific, government, manufacturing, education
Target regions
Russia, Belarus, Thailand, Brazil, Turkey, Spain, Germany, France, Italy, China
Detection rules
9
Indicators of compromise
18

Malware and tooling in DAEMON Tools Lite Supply-Chain Compromise

Malware and tooling: DAEMON Tools Lite First-Stage Infostealer (Kaspersky-attributed Chinese-speaking actor), DAEMON Tools Lite Second-Stage In-Memory Backdoor, QUIC RAT, Custom QUIC-transport RAT framework with multi-protocol fallback (QUIC primary, suspected HTTPS / DNS fallbacks), DAEMON Tools Lite v12.5.0.2421-12.5.0.2434 (free edition)

How DAEMON Tools Lite Supply-Chain Compromise works

Disc Soft Limited's build environment for DAEMON Tools Lite (free edition, v12.5.1) was compromised, resulting in digitally-signed trojanized installers (builds 12.5.0.2421 through 12.5.0.2434) being distributed from the official daemon-tools.cc website between 2026-04-08 and 2026-05-05. Kaspersky researchers identified a multi-stage payload chain: a first-stage infostealer profiling thousands of hosts across 100+ countries, a selective second-stage in-memory backdoor deployed to ~12 high-value retail/scientific/government/manufacturing targets in Russia, Belarus, and Thailand, and a third-stage QUIC RAT with process injection observed at a Russian educational institute. Attribution points to a Chinese-speaking actor; paid Pro/Ultra editions are unaffected and the breach is fixed in v12.6.0.2445.

On 2026-05-05 BleepingComputer disclosed, and on 2026-05-06 vendor Disc Soft Limited confirmed, that the build pipeline for DAEMON Tools Lite (free edition) v12.5.1 was compromised. Three Windows binaries — DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe — were trojanized and re-signed using Disc Soft's legitimate code-signing certificate. The malicious installers carrying these binaries (build numbers 12.5.0.2421 through 12.5.0.2434) were served from the official daemon-tools.cc download infrastructure beginning 2026-04-08, giving the actor approximately one month of unconstrained, signed delivery to global victims before discovery.

Stage 1 — Infostealer / Triage. On execution, the trojanized binaries deploy a lightweight infostealer that collects hostname, MAC address, list of running processes, list of installed software, and system locale. This telemetry is exfiltrated to actor-controlled infrastructure for triage. Telemetry confirms thousands of infections across 100+ countries, with notable density in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.

Stage 2 — Selective In-Memory Backdoor. Approximately twelve high-value hosts (retail, scientific, government, and manufacturing organizations primarily in Russia, Belarus, and Thailand) received a second-stage in-memory backdoor providing arbitrary command execution, file download, and reflective code loading. The second stage is delivered without writing additional files to disk, defeating signature-based AV.

Stage 3 — QUIC RAT. At least one Russian educational institute received a third-stage Remote Access Trojan that uses QUIC (UDP/443) as its primary command-and-control transport with multi-protocol fallback. The RAT uses Windows process injection to migrate execution context out of the Disc Soft binaries and into long-lived host processes, complicating both attribution to the parent installer and incident response.

Attribution. Kaspersky's report attributes the campaign to a Chinese-speaking actor based on language artifacts in the first-stage payload. The actor's selective second-stage targeting of Russian, Belarusian, and Thai government, scientific, and manufacturing entities is consistent with PRC-aligned espionage tradecraft, though Kaspersky has not yet linked the toolset to a named cluster.

Vendor Response. Disc Soft removed the trojanized installers on 2026-05-05 and released DAEMON Tools Lite v12.6.0.2445 the same day. Paid DAEMON Tools Pro, Ultra, and the paid edition of Lite are unaffected because they are built from a separate pipeline. Customers who installed any version in the 12.5.0.2421 to 12.5.0.2434 range during the window must treat their host as potentially backdoored, hunt for QUIC C2 and reflective-loading artifacts, and reimage if second-stage activity is suspected.

Defensive Implications. This incident is a textbook software supply-chain compromise of a freeware utility distributed globally with valid code-signing trust. Detection content should not rely solely on file hashes (the actor controlled signing); detection must focus on behavioural anomalies — outbound QUIC from desktop endpoints to non-CDN infrastructure, reflective loading by DT-process trees, host triage telemetry beacons, and process-injection events sourced from DTHelper.exe / DiscSoftBusServiceLite.exe / DTShellHlp.exe.

MITRE ATT&CK techniques used in TL-2026-0472

Discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery; T1614.001 System Location Discovery: System Language Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1571 Non-Standard Port; T1572 Protocol Tunneling; T1573.002 Encrypted Channel: Asymmetric Cryptography

Execution

T1106 Native API; T1204.002 User Execution: Malicious File

Collection

T1119 Automated Collection

initial-access

T1195 Supply Chain Compromise

Initial Access

T1195.002 Compromise Software Supply Chain

Persistence

T1543.003 Create or Modify System Process: Windows Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

defense-impairment

T1553.002 Subvert Trust Controls: Code Signing

Resource Development

T1587.001 Develop Capabilities: Malware; T1588.003 Obtain Capabilities: Code Signing Certificates

Affected products and versions in DAEMON Tools Lite Supply-Chain Compromise

  • Disc Soft Limited — DAEMON Tools Lite (free edition)
    Vulnerable versions: 12.5.0.2421; 12.5.0.2422; 12.5.0.2423; 12.5.0.2424; 12.5.0.2425; 12.5.0.2426; 12.5.0.2427; 12.5.0.2428; 12.5.0.2429; 12.5.0.2430
    Fixed in: 12.6.0.2445
  • Disc Soft Limited — DAEMON Tools Pro
    Fixed in: all versions unaffected — separate build pipeline
  • Disc Soft Limited — DAEMON Tools Ultra
    Fixed in: all versions unaffected — separate build pipeline
  • Disc Soft Limited — DAEMON Tools Lite (paid edition)
    Fixed in: all versions unaffected — separate build pipeline

Remediation for DAEMON Tools Lite Supply-Chain Compromise

Patches

  • Upgrade DAEMON Tools Lite to v12.6.0.2445 or later, released 2026-05-05 by Disc Soft Limited

Immediate actions

  • Inventory all hosts where DAEMON Tools Lite was installed between 2026-04-08 and 2026-05-05 and identify any version in the 12.5.0.2421 through 12.5.0.2434 range
  • Treat every host that installed a compromised build as potentially backdoored: capture memory, hunt for outbound QUIC (UDP/443) to non-CDN destinations, and look for reflective code loading initiated by DTHelper.exe, DiscSoftBusServiceLite.exe, or DTShellHlp.exe
  • Block downloads of DAEMON Tools Lite installers older than v12.6.0.2445 at the web proxy
  • Reset credentials and rotate browser session cookies for users on confirmed-compromised hosts
  • Hunt SIEM telemetry for first-stage triage beacons (hostname + MAC + process list + installed software + locale) sent from endpoints in the affected window

Workarounds

  • Uninstall DAEMON Tools Lite entirely on hosts where it is not business-critical
  • Block UDP/443 egress from desktop endpoints to anything other than known-good QUIC services until inspection is in place

Longer-term hardening

  • Restrict installation of freeware utilities to a vetted, internal software repository with hash-pinning
  • Deploy EDR with detection content for reflective loading, process injection, and signed-binary anomaly behaviour
  • Implement application allowlisting that validates not only signing-certificate trust but also issuer policy, build provenance (SLSA), and version-range constraints
  • Subscribe to vendor security disclosure feeds and CISA known-supply-chain-compromise notifications
  • Audit and segment outbound UDP/443 (QUIC) egress; require it to traverse a TLS-inspecting proxy where feasible

Weaknesses (CWE) in DAEMON Tools Lite Supply-Chain Compromise

CWE-1357, CWE-494, CWE-829, CWE-506

Timeline of DAEMON Tools Lite Supply-Chain Compromise

  • Trojanized DAEMON Tools Lite installers (builds 12.5.0.2421 through 12.5.0.2434) begin appearing on the official daemon-tools.cc download infrastructure, digitally signed with Disc Soft's legitimate code-signing certificate.
  • First-stage infostealer activity (hostname, MAC address, process list, installed software, system locale collection) observed across thousands of hosts in 100+ countries, with notable density in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.
  • Approximately 12 high-value targets in retail, scientific, government, and manufacturing sectors across Russia, Belarus, and Thailand receive a selective in-memory backdoor providing arbitrary command execution, file download, and reflective code loading.
  • QUIC RAT with Windows process-injection capability and multi-protocol C2 fallback observed at a Russian educational institute as the third-stage payload.
  • Kaspersky researchers identify the campaign during proactive supply-chain hunting and notify Disc Soft Limited.
  • Disc Soft removes the trojanized installers from daemon-tools.cc and releases DAEMON Tools Lite v12.6.0.2445; BleepingComputer publishes initial public disclosure.
  • Kaspersky publicly attributes the campaign to a Chinese-speaking actor based on language artifacts in the first-stage payload; no named cluster linked at time of disclosure.
  • Disc Soft Limited publishes an official incident statement confirming build-environment compromise scoped to the free edition of DAEMON Tools Lite; paid Pro, Ultra, and paid Lite editions confirmed unaffected (separate build pipeline).
  • Threadlinqs Intelligence publishes TL-2026-0472 with full MITRE ATT&CK mapping, IOCs, detections, and simulation guidance.
  • As of 2026-05-29, the malicious distribution channel is contained: Disc Soft secured its build environment, pulled the trojanized v12.5.1 installers, and shipped malware-free v12.6.0.2445, with no reported resurgence. It remains a live concern because the Chinese-speaking actor is unattributed, root cause/vector undisclosed, and in-memory/QUIC-RAT backdoors persist on unremediated victim hosts.

Sources cited for DAEMON Tools Lite Supply-Chain Compromise

Detection coverage for TL-2026-0472

As of 2026-05-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0472 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats