DAEMON Tools Lite Supply-Chain Compromise — Trojanized Signed Installers Deploy Multi-Stage Infostealer + QUIC RAT (Disc Soft, April-May 2026) — Threadlinqs Intelligence
As of 2026-05-30, DAEMON Tools Lite Supply-Chain Compromise — Trojanized Signed Installers Deploy Multi-Stage Infostealer + QUIC RAT (Disc Soft, April-May 2026) is a critical-severity malware threat attributed to a China-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0472 · Severity: CRITICAL · Status: MONITORING · Category: MALWARE
Attribution: China · ESPIONAGE
Disc Soft Limited's build environment for DAEMON Tools Lite (free edition, v12.5.1) was compromised, resulting in digitally-signed trojanized installers (builds 12.5.0.2421 through 12.5.0.2434) being
On 2026-05-05 BleepingComputer disclosed, and on 2026-05-06 vendor Disc Soft Limited confirmed, that the build pipeline for DAEMON Tools Lite (free edition) v12.5.1 was compromised. Three Windows binaries — DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe — were trojanized and re-signed using Disc Soft's legitimate code-signing certificate. The malicious installers carrying these binaries (build numbers 12.5.0.2421 through 12.5.0.2434) were served from the official daemon-tools.cc download infrastructure beginning 2026-04-08, giving the actor approximately one month of unconstrained, signed delivery to global victims before discovery.
Stage 1 — Infostealer / Triage. On execution, the trojanized binaries deploy a lightweight infostealer that collects hostname, MAC address, list of running processes, list of installed software, and system locale. This telemetry is exfiltrated to actor-controlled infrastructure for triage. Telemetry confirms thousands of infections across 100+ countries, with notable density in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.
Stage 2 — Selective In-Memory Backdoor. Approximately twelve high-value hosts (retail, scientific, government, and manufacturing organizations primarily in Russia, Belarus, and Thailand) received a second-stage in-memory backdoor providing arbitrary command execution, file download, and reflective code loading. The second stage is delivered without writing additional files to disk, defeating signature-based AV.
Stage 3 — QUIC RAT. At least one Russian educational institute received a third-stage Remote Access Trojan that uses QUIC (UDP/443) as its primary command-and-control transport with multi-protocol fallback. The RAT uses Windows process injection to migrate execution context out of the Disc Soft binaries and into long-lived host processes, complicating both attribution to the parent installer and incident response.
Attribution. Kaspersky's report attributes the campaign to a Chinese-speaking actor based on language artifacts in the first-stage payload. The actor's selective second-stage targeting of Russian, Belarusian, and Thai government, scientific, and manufacturing entities is consistent with PRC-aligned espionage tradecraft, though Kaspersky has not yet linked the toolset to a named cluster.
Vendor Response. Disc Soft removed the trojanized installers on 2026-05-05 and released DAEMON Tools Lite v12.6.0.2445 the same day. Paid DAEMON Tools Pro, Ultra, and the paid edition of Lite are unaffected because they are built from a separate pipeline. Customers who installed any version in the 12.5.0.2421 to 12.5.0.2434 range during the window must treat their host as potentially backdoored, hunt for QUIC C2 and reflective-loading artifacts, and reimage if second-stage activity is suspected.
Defensive Implications. This incident is a textbook software supply-chain compromise of a freeware utility distributed globally with valid code-signing trust. Detection content should not rely solely on file hashes (the actor controlled signing); detection must focus on behavioural anomalies — outbound QUIC from desktop endpoints to non-CDN infrastructure, reflective loading by DT-process trees, host triage telemetry beacons, and process-injection events sourced from DTHelper.exe / DiscSoftBusServiceLite.exe / DTShellHlp.exe.
Weaknesses (CWE)
CWE-1357, CWE-494, CWE-829, CWE-506
Target sectors: retail, scientific, government, manufacturing, education
Target regions: Russia, Belarus, Thailand, Brazil, Turkey, Spain, Germany, France, Italy, China
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1195, T1587.001, T1588.003, T1195, T1195.002, T1204.002, T1106, T1543.003, T1547.001, T1553.002