Back to Blog
Cybersecurity May 7, 2026 5 min read

DAEMON Tools Supply Chain Attack: Versions 12.5.0.2421–12.5.0.2434 Trojanized With Signed Malware

Kaspersky disclosed that DAEMON Tools installers downloaded between April 8 and May 5, 2026 were compromised with a .NET info-stealer signed by the software's own legitimate certificates. If you installed or updated DAEMON Tools in this window, upgrade to 12.6 immediately and run a full scan.

DAEMON Tools Supply Chain Attack: Versions 12.5.0.2421–12.5.0.2434 Trojanized With Signed Malware

If you installed or updated DAEMON Tools between April 8 and May 5, 2026, your machine may be compromised. Kaspersky disclosed on May 5–6 that DAEMON Tools’ official installer infrastructure was tampered with in a supply chain attack — and the malware was signed with the software’s own legitimate digital certificates.

Affected versions: 12.5.0.2421 through 12.5.0.2434 Fix: Upgrade immediately to version 12.6, released by AVB Disc Soft on May 5, 2026. No CVE has been assigned yet.

Three binaries were trojanized: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. All three carry valid AVB Disc Soft code-signing certificates, which means they pass Windows signature verification and most antivirus checks against known-bad hashes. Standard signature-trust checks will not flag these.

Once installed, the malware beacons to env-check.daemontools[.]cc — a domain registered March 27, 2026, roughly one week after Kaspersky estimates the initial build pipeline was compromised. The first-stage implant profiles the host: language settings, running processes, installed software. It then reaches back for a second-stage .NET info-stealer customized to the target’s environment.

Kaspersky has identified approximately 12 high-value targets that received the full second stage. Infections span more than 100 countries. The heaviest concentrations are in Russia, Brazil, Turkey, Germany, France, Italy, Spain, and China. Targeted sectors include government agencies, scientific research institutions, retail, and manufacturing.

Attribution leans toward a Chinese-speaking threat actor. Kaspersky found Chinese-language strings embedded in the implants and identified infrastructure patterns consistent with previously documented Chinese APT tooling. No formal group attribution has been made public.

The attack follows a pattern similar to the 2019 ASUS Live Update compromise (Operation ShadowHammer), where attackers gained access to a vendor’s build or update distribution pipeline and signed the payload with legitimate certificates. The result is a weapon that is invisible to perimeter defenses, passes integrity checks, and arrives through a trusted software update.

DAEMON Tools reports approximately 22 million registered users worldwide. Most are home users and developers managing disk images — not typical high-value espionage targets. That suggests the attackers used DAEMON Tools as a distribution mechanism to reach a small number of high-value machines embedded within a much larger legitimate install base.

Immediate steps:

  1. Check your version: open DAEMON Tools → Help → About
  2. If version is 12.5.0.2421 through 12.5.0.2434, uninstall immediately and run a full malware scan with an updated engine
  3. Upgrade to version 12.6 from the official daemontools.com download page
  4. Block outbound DNS and HTTP to env-check.daemontools[.]cc at your firewall or EDR
  5. Review endpoint telemetry for the three named binaries, unusual outbound connections, and any new scheduled tasks or persistence mechanisms created in April–May 2026
supply chain attack malware DAEMON Tools Kaspersky