Threat reportMalwareTL-2026-0472
DAEMON Tools Lite Supply-Chain Compromise — Trojanized Signed Installers Deploy Multi-Stage Infostealer + QUIC RAT (Disc Soft, April-May 2026)
DAEMON Tools Lite Supply-Chain Compromise (TL-2026-0472), also tracked as DAEMON Tools Lite Supply-Chain Compromise, is a critical-severity malware campaign, first published 2026-05-07. It carries a reported China nexus and is not formally attributed, affects Disc Soft Limited DAEMON Tools Lite (free edition), maps to 25 MITRE ATT&CK techniques (T1016, T1027, T1036.005), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-0472
- Threat ID
- TL-2026-0472
- Also known as
- DAEMON Tools Lite Supply-Chain Compromise, Disc Soft Build Environment Breach (April 2026), DTHelper Trojanization Campaign
- Severity
- CRITICAL
- Status
- MONITORING
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- retail, scientific, government, manufacturing, education
- Target regions
- Russia, Belarus, Thailand, Brazil, Turkey, Spain, Germany, France, Italy, China
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in DAEMON Tools Lite Supply-Chain Compromise
Malware and tooling: DAEMON Tools Lite First-Stage Infostealer (Kaspersky-attributed Chinese-speaking actor), DAEMON Tools Lite Second-Stage In-Memory Backdoor, QUIC RAT, Custom QUIC-transport RAT framework with multi-protocol fallback (QUIC primary, suspected HTTPS / DNS fallbacks), DAEMON Tools Lite v12.5.0.2421-12.5.0.2434 (free edition)
How DAEMON Tools Lite Supply-Chain Compromise works
Disc Soft Limited's build environment for DAEMON Tools Lite (free edition, v12.5.1) was compromised, resulting in digitally-signed trojanized installers (builds 12.5.0.2421 through 12.5.0.2434) being distributed from the official daemon-tools.cc website between 2026-04-08 and 2026-05-05. Kaspersky researchers identified a multi-stage payload chain: a first-stage infostealer profiling thousands of hosts across 100+ countries, a selective second-stage in-memory backdoor deployed to ~12 high-value retail/scientific/government/manufacturing targets in Russia, Belarus, and Thailand, and a third-stage QUIC RAT with process injection observed at a Russian educational institute. Attribution points to a Chinese-speaking actor; paid Pro/Ultra editions are unaffected and the breach is fixed in v12.6.0.2445.
On 2026-05-05 BleepingComputer disclosed, and on 2026-05-06 vendor Disc Soft Limited confirmed, that the build pipeline for DAEMON Tools Lite (free edition) v12.5.1 was compromised. Three Windows binaries — DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe — were trojanized and re-signed using Disc Soft's legitimate code-signing certificate. The malicious installers carrying these binaries (build numbers 12.5.0.2421 through 12.5.0.2434) were served from the official daemon-tools.cc download infrastructure beginning 2026-04-08, giving the actor approximately one month of unconstrained, signed delivery to global victims before discovery.
Stage 1 — Infostealer / Triage. On execution, the trojanized binaries deploy a lightweight infostealer that collects hostname, MAC address, list of running processes, list of installed software, and system locale. This telemetry is exfiltrated to actor-controlled infrastructure for triage. Telemetry confirms thousands of infections across 100+ countries, with notable density in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.
Stage 2 — Selective In-Memory Backdoor. Approximately twelve high-value hosts (retail, scientific, government, and manufacturing organizations primarily in Russia, Belarus, and Thailand) received a second-stage in-memory backdoor providing arbitrary command execution, file download, and reflective code loading. The second stage is delivered without writing additional files to disk, defeating signature-based AV.
Stage 3 — QUIC RAT. At least one Russian educational institute received a third-stage Remote Access Trojan that uses QUIC (UDP/443) as its primary command-and-control transport with multi-protocol fallback. The RAT uses Windows process injection to migrate execution context out of the Disc Soft binaries and into long-lived host processes, complicating both attribution to the parent installer and incident response.
Attribution. Kaspersky's report attributes the campaign to a Chinese-speaking actor based on language artifacts in the first-stage payload. The actor's selective second-stage targeting of Russian, Belarusian, and Thai government, scientific, and manufacturing entities is consistent with PRC-aligned espionage tradecraft, though Kaspersky has not yet linked the toolset to a named cluster.
Vendor Response. Disc Soft removed the trojanized installers on 2026-05-05 and released DAEMON Tools Lite v12.6.0.2445 the same day. Paid DAEMON Tools Pro, Ultra, and the paid edition of Lite are unaffected because they are built from a separate pipeline. Customers who installed any version in the 12.5.0.2421 to 12.5.0.2434 range during the window must treat their host as potentially backdoored, hunt for QUIC C2 and reflective-loading artifacts, and reimage if second-stage activity is suspected.
Defensive Implications. This incident is a textbook software supply-chain compromise of a freeware utility distributed globally with valid code-signing trust. Detection content should not rely solely on file hashes (the actor controlled signing); detection must focus on behavioural anomalies — outbound QUIC from desktop endpoints to non-CDN infrastructure, reflective loading by DT-process trees, host triage telemetry beacons, and process-injection events sourced from DTHelper.exe / DiscSoftBusServiceLite.exe / DTShellHlp.exe.
MITRE ATT&CK techniques used in TL-2026-0472
Discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery; T1614.001 System Location Discovery: System Language Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1571 Non-Standard Port; T1572 Protocol Tunneling; T1573.002 Encrypted Channel: Asymmetric Cryptography
Execution
T1106 Native API; T1204.002 User Execution: Malicious File
Collection
initial-access
Initial Access
T1195.002 Compromise Software Supply Chain
Persistence
T1543.003 Create or Modify System Process: Windows Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing
Resource Development
T1587.001 Develop Capabilities: Malware; T1588.003 Obtain Capabilities: Code Signing Certificates
Affected products and versions in DAEMON Tools Lite Supply-Chain Compromise
- Disc Soft Limited — DAEMON Tools Lite (free edition)
Vulnerable versions: 12.5.0.2421; 12.5.0.2422; 12.5.0.2423; 12.5.0.2424; 12.5.0.2425; 12.5.0.2426; 12.5.0.2427; 12.5.0.2428; 12.5.0.2429; 12.5.0.2430
Fixed in: 12.6.0.2445 - Disc Soft Limited — DAEMON Tools Pro
Fixed in: all versions unaffected — separate build pipeline - Disc Soft Limited — DAEMON Tools Ultra
Fixed in: all versions unaffected — separate build pipeline - Disc Soft Limited — DAEMON Tools Lite (paid edition)
Fixed in: all versions unaffected — separate build pipeline
Remediation for DAEMON Tools Lite Supply-Chain Compromise
Patches
- Upgrade DAEMON Tools Lite to v12.6.0.2445 or later, released 2026-05-05 by Disc Soft Limited
Immediate actions
- Inventory all hosts where DAEMON Tools Lite was installed between 2026-04-08 and 2026-05-05 and identify any version in the 12.5.0.2421 through 12.5.0.2434 range
- Treat every host that installed a compromised build as potentially backdoored: capture memory, hunt for outbound QUIC (UDP/443) to non-CDN destinations, and look for reflective code loading initiated by DTHelper.exe, DiscSoftBusServiceLite.exe, or DTShellHlp.exe
- Block downloads of DAEMON Tools Lite installers older than v12.6.0.2445 at the web proxy
- Reset credentials and rotate browser session cookies for users on confirmed-compromised hosts
- Hunt SIEM telemetry for first-stage triage beacons (hostname + MAC + process list + installed software + locale) sent from endpoints in the affected window
Workarounds
- Uninstall DAEMON Tools Lite entirely on hosts where it is not business-critical
- Block UDP/443 egress from desktop endpoints to anything other than known-good QUIC services until inspection is in place
Longer-term hardening
- Restrict installation of freeware utilities to a vetted, internal software repository with hash-pinning
- Deploy EDR with detection content for reflective loading, process injection, and signed-binary anomaly behaviour
- Implement application allowlisting that validates not only signing-certificate trust but also issuer policy, build provenance (SLSA), and version-range constraints
- Subscribe to vendor security disclosure feeds and CISA known-supply-chain-compromise notifications
- Audit and segment outbound UDP/443 (QUIC) egress; require it to traverse a TLS-inspecting proxy where feasible
Weaknesses (CWE) in DAEMON Tools Lite Supply-Chain Compromise
Timeline of DAEMON Tools Lite Supply-Chain Compromise
- Trojanized DAEMON Tools Lite installers (builds 12.5.0.2421 through 12.5.0.2434) begin appearing on the official daemon-tools.cc download infrastructure, digitally signed with Disc Soft's legitimate code-signing certificate.
- First-stage infostealer activity (hostname, MAC address, process list, installed software, system locale collection) observed across thousands of hosts in 100+ countries, with notable density in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.
- Approximately 12 high-value targets in retail, scientific, government, and manufacturing sectors across Russia, Belarus, and Thailand receive a selective in-memory backdoor providing arbitrary command execution, file download, and reflective code loading.
- QUIC RAT with Windows process-injection capability and multi-protocol C2 fallback observed at a Russian educational institute as the third-stage payload.
- Kaspersky researchers identify the campaign during proactive supply-chain hunting and notify Disc Soft Limited.
- Disc Soft removes the trojanized installers from daemon-tools.cc and releases DAEMON Tools Lite v12.6.0.2445; BleepingComputer publishes initial public disclosure.
- Kaspersky publicly attributes the campaign to a Chinese-speaking actor based on language artifacts in the first-stage payload; no named cluster linked at time of disclosure.
- Disc Soft Limited publishes an official incident statement confirming build-environment compromise scoped to the free edition of DAEMON Tools Lite; paid Pro, Ultra, and paid Lite editions confirmed unaffected (separate build pipeline).
- Threadlinqs Intelligence publishes TL-2026-0472 with full MITRE ATT&CK mapping, IOCs, detections, and simulation guidance.
- As of 2026-05-29, the malicious distribution channel is contained: Disc Soft secured its build environment, pulled the trojanized v12.5.1 installers, and shipped malware-free v12.6.0.2445, with no reported resurgence. It remains a live concern because the Chinese-speaking actor is unattributed, root cause/vector undisclosed, and in-memory/QUIC-RAT backdoors persist on unremediated victim hosts.
Sources cited for DAEMON Tools Lite Supply-Chain Compromise
- DAEMON Tools trojanized in supply-chain attack to deploy backdoor
- DAEMON Tools devs confirm breach, release malware-free version
- Security Incident Affecting DAEMON Tools Lite: What We Know So Far (Disc Soft official statement)
- MITRE ATT&CK T1195.002 — Compromise Software Supply Chain
- MITRE ATT&CK T1553.002 — Subvert Trust Controls: Code Signing
- MITRE ATT&CK T1620 — Reflective Code Loading
- CISA — Defending Against Software Supply Chain Attacks
- CWE-1357 — Reliance on Insufficiently Trustworthy Component
Detection coverage for TL-2026-0472
As of 2026-05-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0472 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.