# DAEMON Tools Lite Supply-Chain Compromise — Trojanized Signed Installers Deploy Multi-Stage Infostealer + QUIC RAT (Disc Soft, April-May 2026)

> Disc Soft Limited's build environment for DAEMON Tools Lite (free edition, v12.5.1) was compromised, resulting in digitally-signed trojanized installers (builds 12.5.0.2421 through 12.5.0.2434) being distributed from the official daemon-tools.cc website between 2026-04-08 and 2026-05-05. Kaspersky researchers identified a multi-stage payload chain: a first-stage infostealer profiling thousands of hosts across 100+ countries, a selective second-stage in-memory backdoor deployed to ~12 high-value retail/scientific/government/manufacturing targets in Russia, Belarus, and Thailand, and a third-stage QUIC RAT with process injection observed at a Russian educational institute. Attribution points to a Chinese-speaking actor; paid Pro/Ultra editions are unaffected and the breach is fixed in v12.6.0.2445.

- **Published:** 2026-05-07T12:00:00Z
- **Last reviewed:** 2026-05-07T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0472
- **ID:** TL-2026-0472
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-05-05 BleepingComputer disclosed, and on 2026-05-06 vendor Disc Soft Limited confirmed, that the build pipeline for DAEMON Tools Lite (free edition) v12.5.1 was compromised. Three Windows binaries — DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe — were trojanized and re-signed using Disc Soft's legitimate code-signing certificate. The malicious installers carrying these binaries (build numbers 12.5.0.2421 through 12.5.0.2434) were served from the official daemon-tools.cc download infrastructure beginning 2026-04-08, giving the actor approximately one month of unconstrained, signed delivery to global victims before discovery.

Stage 1 — Infostealer / Triage. On execution, the trojanized binaries deploy a lightweight infostealer that collects hostname, MAC address, list of running processes, list of installed software, and system locale. This telemetry is exfiltrated to actor-controlled infrastructure for triage. Telemetry confirms thousands of infections across 100+ countries, with notable density in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.

Stage 2 — Selective In-Memory Backdoor. Approximately twelve high-value hosts (retail, scientific, government, and manufacturing organizations primarily in Russia, Belarus, and Thailand) received a second-stage in-memory backdoor providing arbitrary command execution, file download, and reflective code loading. The second stage is delivered without writing additional files to disk, defeating signature-based AV.

Stage 3 — QUIC RAT. At least one Russian educational institute received a third-stage Remote Access Trojan that uses QUIC (UDP/443) as its primary command-and-control transport with multi-protocol fallback. The RAT uses Windows process injection to migrate execution context out of the Disc Soft binaries and into long-lived host processes, complicating both attribution to the parent installer and incident response.

Attribution. Kaspersky's report attributes the campaign to a Chinese-speaking actor based on language artifacts in the first-stage payload. The actor's selective second-stage targeting of Russian, Belarusian, and Thai government, scientific, and manufacturing entities is consistent with PRC-aligned espionage tradecraft, though Kaspersky has not yet linked the toolset to a named cluster.

Vendor Response. Disc Soft removed the trojanized installers on 2026-05-05 and released DAEMON Tools Lite v12.6.0.2445 the same day. Paid DAEMON Tools Pro, Ultra, and the paid edition of Lite are unaffected because they are built from a separate pipeline. Customers who installed any version in the 12.5.0.2421 to 12.5.0.2434 range during the window must treat their host as potentially backdoored, hunt for QUIC C2 and reflective-loading artifacts, and reimage if second-stage activity is suspected.

Defensive Implications. This incident is a textbook software supply-chain compromise of a freeware utility distributed globally with valid code-signing trust. Detection content should not rely solely on file hashes (the actor controlled signing); detection must focus on behavioural anomalies — outbound QUIC from desktop endpoints to non-CDN infrastructure, reflective loading by DT-process trees, host triage telemetry beacons, and process-injection events sourced from DTHelper.exe / DiscSoftBusServiceLite.exe / DTShellHlp.exe.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1587.001 Develop Capabilities: Malware
- T1588.003 Obtain Capabilities: Code Signing Certificates
- T1195.002 Compromise Software Supply Chain
- T1204.002 User Execution: Malicious File
- T1106 Native API
- T1543.003 Create or Modify System Process: Windows Service
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1553.002 Subvert Trust Controls: Code Signing
- T1620 Reflective Code Loading
- T1055 Process Injection
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1082 System Information Discovery
- T1057 Process Discovery
- T1518 Software Discovery
- T1614.001 System Location Discovery: System Language Discovery
- T1016 System Network Configuration Discovery
- T1119 Automated Collection
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.002 Encrypted Channel: Asymmetric Cryptography
- T1571 Non-Standard Port
- T1572 Protocol Tunneling
- T1041 Exfiltration Over C2 Channel

## Sources

- [DAEMON Tools trojanized in supply-chain attack to deploy backdoor](https://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/)
- [DAEMON Tools devs confirm breach, release malware-free version](https://www.bleepingcomputer.com/news/security/daemon-tools-devs-confirm-breach-release-malware-free-version/)
- [Security Incident Affecting DAEMON Tools Lite: What We Know So Far (Disc Soft official statement)](https://www.daemon-tools.cc/news)
- [MITRE ATT&CK T1195.002 — Compromise Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK T1553.002 — Subvert Trust Controls: Code Signing](https://attack.mitre.org/techniques/T1553/002/)
- [MITRE ATT&CK T1620 — Reflective Code Loading](https://attack.mitre.org/techniques/T1620/)
- [CISA — Defending Against Software Supply Chain Attacks](https://www.cisa.gov/resources-tools/resources/defending-against-software-supply-chain-attacks)
- [CWE-1357 — Reliance on Insufficiently Trustworthy Component](https://cwe.mitre.org/data/definitions/1357.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0472
