Posts: 16,283
Threads: 10,312
Thanks Received: 9,367 in 7,513 posts
Thanks Given: 10,347
Joined: 12 September 18
Today, 11:35
Quote:What happened?
In early May 2026, we identified installers of the DAEMON Tools software, used for mounting disk images, to be compromised with a malicious payload. These installers are distributed from the legitimate website of DAEMON Tools and are signed with digital certificates belonging to DAEMON Tools developers. Our analysis revealed that the software installers have been trojanized starting from April 8, 2026. Specifically, we identified versions of DAEMON Tools ranging from 12.5.0.2421 to 12.5.0.2434 to be compromised. At the time of writing this article, the supply chain attack is still active. Artifacts suggesting that the threat actor behind this attack is Chinese-speaking have been identified in the malicious implants observed. We contacted AVB Disc Soft, the developer company of DAEMON Tools, so that further actions could be taken to remediate the attack consequences.
![[Image: 1.png]](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/05/05033425/1.png)
Starting from early April, we observed several thousands of infection attempts involving DAEMON Tools in our telemetry, with individuals and organizations in more than 100 countries being affected. However, out of all the machines infected, we have observed further-stage payloads being deployed to only a dozen of them. These machines that received further payloads belonged to retail, scientific, government and manufacturing organizations – and this indicates that the supply chain attack has a targeted manner.
Kaspersky solutions protect its users from the malicious payloads deployed through the DAEMON Tools supply chain attack.
Trojanized binaries
Our analysis revealed that for DAEMON Tools versions from 12.5.0.2421 to 12.5.0.2434, attackers have managed to compromise the following binaries inside the software installations:- DTHelper.exe
- DiscSoftBusServiceLite.exe
- DTShellHlp.exe
These files are located in the directory where DAEMON Tools is installed, for example
Code:
C:\Program Files\DAEMON Tools Lite
. Notably, these files are digitally signed by the developer of DAEMON Tools, AVB Disc Soft.
Continue Reading...