Popular DAEMON Tools software compromised

May 5, 2026, 4:08 p.m.

Description

Since April 8, 2026, installers of DAEMON Tools software have been compromised with malicious payloads distributed through the legitimate website. Versions 12.5.0.2421 to 12.5.0.2434 contain trojaned binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) signed with legitimate developer certificates. The attack has affected thousands of systems across over 100 countries, though advanced payloads were selectively deployed to approximately a dozen machines in government, scientific, manufacturing, and retail organizations. Initial infection establishes backdoor communications to typosquatted domains, followed by deployment of an information collector for system profiling. Targeted systems receive additional implants including a minimalistic backdoor and QUIC RAT. Chinese-language strings found in malicious components suggest a Chinese-speaking threat actor. The attack remains active at time of publication, demonstrating sophisticated supply chain compromise techniques comparable to the 2023 3CX ...

Date

  • Created: May 5, 2026, 2:23 p.m.
  • Published: May 5, 2026, 2:23 p.m.
  • Modified: May 5, 2026, 4:08 p.m.

Indicators

  • d2a5c9cbb73849cc0667987c33a9bf3822718e1528faef005f1628de3348ffb0
  • 12edcaafab7703d0819b1395f45c35e3083dd83fb8b128292cb11033453fb6e8
  • a916e56121212613d17932e124b68752c9312e73bde8f2351054bd64394257df

Additional Informations

  • Education
  • Manufacturing
  • Retail
  • Government
  • Belarus
  • Russian Federation
  • Thailand