The DAEMON Tools Supply Chain Attack
Updated 5 Oct 2026 · Incident date 8 Apr 2026 · vendor binary
DAEMON Tools 12.5.0.2421 through 12.5.0.2434, signed by AVB Disc Soft; fixed in 12.6.0.2445DTHelper.exeDAEMON Tools Lite 12.5.0.2421 through 12.5.0.2434 for Windows carried a backdoor. The installers came from the official download site and carried valid signatures from the vendor. The fixed version is 12.6.0.2445.
Three programs inside the product gained code that contacts an attacker website at startup and runs the commands it receives.
What happened
From 8 April 2026, the official DAEMON Tools download site gave out trojanized installers. Help Net Security reports that Kaspersky published the findings on 6 May 2026. The signed files carried legitimate Disc Soft certificates. The trojanized installers were live for about one month.
Three existing programs were changed: DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe. The Hacker News reports that the programs send HTTP GET requests to env-check.daemontools[.]cc when they start. They then run the shell commands they receive through cmd.exe. The domain was registered on 27 March 2026.
The first stage is a .NET program that collects data from the machine. BleepingComputer lists the data as hostname, MAC address, running processes, installed software and system locale. A few machines then received a small backdoor that can run commands, download files and inject code into memory.
The attackers chose their targets. The reports describe thousands of infection attempts in more than 100 countries. Fewer than 12 machines received the second stage. Those victims were retail, scientific, government and manufacturing organizations in Russia, Belarus and Thailand. At least one Russian educational institution received a further tool called QUIC RAT. Kaspersky saw Chinese-language strings in the first-stage code. No known group has been named as the actor.
The vendor, Disc Soft, said that certain installation packages were affected within its build environment. It released 12.6.0.2445 after the disclosure. It says the Pro and Ultra editions were not affected.
Affected versions
- DAEMON Tools Lite 12.5.0.2421 through 12.5.0.2434, Windows only.
- The Hacker News reports that the macOS version was not affected.
- Fixed in 12.6.0.2445.
- Exposure window starts on 8 April 2026.
Indicators of compromise
- Command and control domain:
env-check.daemontools[.]cc. - Changed files:
DTHelper.exe,DiscSoftBusServiceLite.exeandDTShellHlp.exe. - Dropped files named in the reports:
envchk.exe,cdg.exeandcdg.tmp. - Injection targets of the later stage:
notepad.exeandconhost.exe. - Install version in the range 12.5.0.2421 to 12.5.0.2434.
- Help Net Security also lists
Deamon-tools[.]ccas a compromised site.
How to check
Find the version of the changed files on each Windows machine, then search DNS records for the attack domain. Run these in PowerShell.
Get-ChildItem C:\ -Recurse -Filter DTHelper.exe -ErrorAction SilentlyContinue | Select-Object FullName, @{n='Version';e={$_.VersionInfo.FileVersion}}
Get-DnsClientCache | Where-Object Entry -like '*daemontools.cc*'The version string of a file can differ from the product version in the installer. Check the product version in Apps and Features as well. Search firewall and proxy logs for the domain too, since the DNS cache holds only recent names.
What to do now
- Update to 12.6.0.2445 or a later release from the vendor.
- Examine every machine that had DAEMON Tools installed. Kaspersky advises that you look for abnormal security activity on or after 8 April 2026.
- Search network logs for
env-check.daemontools[.]cc. - If you find a match, treat the machine as compromised and rotate the credentials it held.
- Do not rely on a valid signature alone. Here the poisoned files carried the vendor signature. Vigilance compares the new build with the build you trust and reports the file that gained a new capability. In this case, three existing programs gained outbound command polling and shell command execution.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 88 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED DTHelper.exe It now downloads from the internet and restarts itself after a reboot. It did not before.
Frequently asked questions
Which DAEMON Tools versions were compromised?
DAEMON Tools Lite 12.5.0.2421 through 12.5.0.2434 on Windows. The fixed version is 12.6.0.2445.
Were the DAEMON Tools installers signed?
Yes. The trojanized files carried legitimate Disc Soft signatures, so a valid signature did not show the files were clean.
How do I know if DAEMON Tools infected my computer?
Check for a Lite version between 12.5.0.2421 and 12.5.0.2434 and search DNS and network logs for env-check.daemontools[.]cc. Then look at security activity from 8 April 2026 onward.
Were DAEMON Tools Pro and Ultra affected?
The vendor says no. It limited the incident to the Lite version.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
- QuickFox VPN trojanized Windows installer 1 Aug 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.