A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from Kaspersky. The installers are distributed from the legitimate DAEMON Tools website and are signed with digital certificates belonging to DAEMON Tools developers—making this a textbook supply chain compromise that bypasses traditional security controls.
The Compromise
The installers have been trojanized since April 8, 2026, with versions ranging from 12.5.0.2421 to 12.5.0.2434 identified as compromised. While DAEMON Tools is also available for Mac, only the Windows version was affected. The supply chain attack remains active as of this writing.
AVB Disc Soft, the Latvian developer of DAEMON Tools, has been notified of the breach and stated they are “aware of the report and are currently investigating the situation” with “highest priority.”
Compromised Components
Three different components of DAEMON Tools have been tampered with:
- DTHelper.exe – Helper utility for DAEMON Tools operations
- DiscSoftBusServiceLite.exe – Bus service component
- DTShellHlp.exe – Shell integration helper
Any time one of these binaries is launched—which typically happens during system startup—an implant is activated on the compromised host.
Attack Chain Breakdown
Stage 1: Initial Beacon
The trojanized components send an HTTP GET request to an external server: env-check.daemontools[.]cc—a domain registered on March 27, 2026, approximately two weeks before the compromised installers began distribution. This request receives a shell command that’s executed using cmd.exe.
Stage 2: Payload Download
The shell command downloads and runs a series of executable payloads:
- envchk.exe – A .NET executable designed to collect extensive system information (reconnaissance)
- cdg.exe – A shellcode loader responsible for decrypting payload contents
- cdg.tmp – Encrypted payload file decrypted by cdg.exe
Stage 3: Backdoor Deployment
The decrypted payload launches a minimalist backdoor that:
- Contacts a remote command-and-control (C2) server
- Downloads additional files
- Executes shell commands remotely
- Runs shellcode payloads directly in memory (fileless execution)
Infection Scale and Targeting
Kaspersky observed several thousand infection attempts involving DAEMON Tools in their telemetry, impacting individuals and organizations in more than 100 countries, including:
- Russia
- Brazil
- Turkey
- Spain
- Germany
- France
- Italy
- China
However, the next-stage backdoor has been delivered only to a dozen hosts, indicating a highly targeted approach. This two-tier infection strategy suggests:
- Wide net: Compromise as many systems as possible initially
- Selective targeting: Deploy advanced capabilities only to high-value victims
- Stealth: Minimize detection by limiting suspicious activity on most infected machines
Identified Victims
The systems that received the follow-on malware belong to:
- Retail organizations (Russia, Belarus, Thailand)
- Scientific institutions (Russia, Belarus, Thailand)
- Government entities (Russia, Belarus, Thailand)
- Manufacturing companies (Russia, Belarus, Thailand)
- Educational institution (Russia – sole QUIC RAT victim)
QUIC RAT: Advanced Capabilities
One of the payloads delivered via the backdoor is a remote access trojan dubbed QUIC RAT. The use of this C++ implant has been recorded against a lone victim: an educational institution in Russia.
QUIC RAT Features:
- Multi-Protocol C2: Supports HTTP, UDP, TCP, WSS (WebSocket Secure), QUIC, DNS, and HTTP/3
- Process Injection: Can inject payloads into legitimate
notepad.exeandconhost.exeprocesses - Fileless Execution: Runs shellcode directly in memory to avoid disk-based detection
- Flexible Communication: QUIC and HTTP/3 support evades traditional firewall inspection
The multi-protocol capability is particularly concerning—it allows the malware to adapt to different network environments and evade detection by switching protocols if one is blocked or monitored.
Attribution: Chinese-Speaking Adversary
The activity has not been formally attributed to any known threat actor or group. However, evidence points to it being the work of a Chinese-speaking adversary based on analysis of artifacts observed during the investigation.
Kaspersky noted: “This manner of deploying the backdoor to a small subset of infected machines clearly indicates that the attacker had intentions to conduct the infection in a targeted manner. However, their intent—whether it is cyberespionage or ‘big game hunting’—is currently unclear.”
The ambiguity between espionage and financially-motivated attacks makes this threat particularly unpredictable. Both objectives require different operational patterns, and the attackers may pivot based on opportunities discovered during reconnaissance.
Why This Matters
The DAEMON Tools supply chain attack represents several critical security challenges:
1. Trust Exploitation
Users implicitly trust:
- Software downloaded from official vendor websites
- Digitally signed executables (verified publisher)
- Well-known software brands (DAEMON Tools has existed since 2004)
This trust is weaponized by attackers. As Kaspersky’s Georgy Kucherin explained: “A compromise of this nature bypasses traditional perimeter defenses because users implicitly trust digitally signed software downloaded directly from an official vendor.”
2. Detection Evasion
The attack went unnoticed for approximately one month (April 8 to early May 2026). This extended dwell time indicates:
- Sophisticated operational security by attackers
- Limitations in current supply chain monitoring
- Insufficient behavioral analysis of signed software
3. Scale vs. Precision
Several thousand infections, but only a dozen received the advanced backdoor. This demonstrates:
- Industrial-scale initial compromise capability
- Manual or automated victim triage processes
- Resource optimization (don’t waste advanced tools on low-value targets)
4. Legitimate Infrastructure Abuse
The attackers used:
- DAEMON Tools’ own distribution infrastructure
- Valid code signing certificates
- Legitimate startup mechanisms (Windows services)
This makes detection exponentially harder—malicious traffic blends with legitimate vendor communications.
Immediate Mitigation Steps
1. Identify and Isolate
Check for compromised DAEMON Tools versions:
# Check installed version
reg query "HKLM\SOFTWARE\Disc Soft\DAEMON Tools Lite" /v Version
# Or check via Control Panel → Programs and FeaturesVulnerable versions: 12.5.0.2421 through 12.5.0.2434
Action: If installed, isolate the machine from the network immediately.
2. Uninstall Compromised Software
Remove DAEMON Tools completely:
# Use official uninstaller or Windows Settings
# Then manually verify removal of:
C:\Program Files\DAEMON Tools Lite\
C:\Program Files (x86)\DAEMON Tools Lite\
%AppData%\Disc Soft\3. Hunt for Indicators of Compromise (IOCs)
Search for malicious artifacts:
# Check for suspicious network connections
netstat -ano | findstr "env-check.daemontools"
# Search for malicious files
dir /s /b envchk.exe 2>nul
dir /s /b cdg.exe 2>nul
dir /s /b cdg.tmp 2>nul
# Check startup locations for trojanized components
reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
reg query HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run4. Monitor Network Traffic
Block and alert on C2 communications:
env-check.daemontools[.]cc(primary C2)- Unusual HTTP/HTTPS traffic from DAEMON Tools processes
- QUIC protocol traffic (UDP/443) from unexpected sources
- DNS queries for suspicious domains
5. Conduct Security Sweeps
For organizations with confirmed infections:
- Full forensic analysis of compromised hosts
- Review lateral movement indicators
- Check for persistence mechanisms beyond DAEMON Tools
- Scan for QUIC RAT and other second-stage payloads
- Reset credentials used on infected systems
Reflection: The Supply Chain Crisis of 2026
The DAEMON Tools compromise is the latest in a growing list of software supply chain incidents in the first half of 2026:
- January 2026: eScan antivirus update servers compromised
- February 2026: Notepad++ hijacked update mechanism
- April 2026: CPUID breach distributes STX RAT
- May 2026: DAEMON Tools installers trojanized
This pattern demands serious reflection on the state of software supply chain security.
1. The Signing Certificate Problem
All compromised DAEMON Tools installers were digitally signed with valid certificates belonging to the developers. This reveals a fundamental flaw:
Current Model: Code signing = Trust
Reality: Code signing = Authenticity (not security)
Digital signatures prove that software came from the claimed publisher and hasn’t been modified after signing. They do not prove that the software is free from malware—especially when the publisher’s own build environment is compromised.
Questions we must answer:
- Should code signing include attestation about build environment security?
- Do we need real-time certificate revocation for compromised publishers?
- Should operating systems warn users when signed software exhibits suspicious behavior?
2. The Update Mechanism Vulnerability
Supply chain attacks succeed because software update mechanisms are inherently trusted:
- Auto-updaters run with elevated privileges
- Update traffic is rarely inspected (it’s “from the vendor”)
- Users click “Update Now” without hesitation
- Security tools whitelist vendor domains
This creates a perfect attack vector. Compromise the update server or build pipeline, and you can distribute malware to every user—legitimately.
The paradox: The same mechanism that keeps software secure (automatic updates) becomes the vector for mass compromise when attackers gain access.
3. The Dwell Time Problem
One month of undetected distribution is not unusual for supply chain attacks:
- SolarWinds SUNBURST: ~9 months undetected
- CCleaner: ~1 month undetected
- ASUS ShadowHammer: ~2 months undetected
- DAEMON Tools: ~1 month undetected (so far)
Why does detection take so long?
- Vendors don’t continuously monitor their own distribution integrity
- Security tools trust signed software by default
- Behavioral analysis is often disabled for known vendors
- Victims assume “it’s from the official site, so it’s safe”
The hard truth: Supply chain attacks are detected by outsiders (security researchers, intelligence agencies) more often than by the compromised vendors themselves.
4. The Targeting Dilemma
DAEMON Tools attackers infected thousands but only deployed advanced backdoors to a dozen hosts. This raises operational security questions:
Why not weaponize everyone?
- Resource constraints (managing thousands of RATs is hard)
- Risk amplification (more activity = higher detection probability)
- Value prioritization (focus on high-value targets)
- Plausible deniability (most infections look like “just malware”)
This selective approach makes attribution and response harder. Most victims experience “generic” malware, while only a handful face advanced persistent threats. This fragmentation complicates incident response and threat intelligence sharing.
5. The Geographic Pattern
Identified victims span Russia, Belarus, and Thailand—primarily retail, scientific, government, and manufacturing sectors. This distribution suggests:
- Regional focus: Eastern Europe and Southeast Asia
- Sector diversity: Not limited to one industry
- Potential espionage: Government and scientific targets
- Potential financial: Retail and manufacturing targets
The Chinese-speaking attribution combined with Russian/Belarusian/Thai victims creates an interesting geopolitical dynamic. Possibilities include:
- Chinese APT targeting Russian entities (state-sponsored espionage)
- Criminal group with regional focus (financially motivated)
- False flag operation (deliberate misattribution)
- Third-party broker (selling access to multiple buyers)
Without clearer attribution, defenders must prepare for multiple threat scenarios simultaneously.
6. The QUIC Protocol Challenge
QUIC RAT’s support for QUIC (Quick UDP Internet Connections) and HTTP/3 represents an emerging detection challenge:
- QUIC encrypts everything: Including metadata that traditional firewalls inspect
- UDP-based: Evades TCP-focused security tools
- Legitimate use growing: Chrome, Firefox, and major services use QUIC
- Inspection difficulty: Deep packet inspection requires MITM, which breaks QUIC
As more malware adopts QUIC and HTTP/3, network security teams face a choice:
- Block these protocols (sacrificing performance and compatibility)
- Allow them (accepting reduced visibility)
- Invest in endpoint detection (shifting security perimeter)
There is no easy answer—this is a structural shift in how internet traffic works, and security architectures haven’t fully adapted.
Lessons for Organizations
1. Trust, But Verify
Even software from official sources requires scrutiny:
- Monitor behavior of all software, regardless of signature status
- Implement application allowlisting where feasible
- Use sandboxing for software installation and updates
- Verify file hashes against multiple sources
2. Segment and Isolate
Limit the blast radius of supply chain compromises:
- Network segmentation between user workstations and critical systems
- Privileged access workstations (PAWs) for admin tasks
- Application isolation (containers, VMs) for high-risk software
- Egress filtering to detect C2 communications
3. Continuous Monitoring
Assume compromise and detect quickly:
- EDR/XDR solutions with behavioral analysis
- Network traffic analysis for anomalous patterns
- Regular threat hunting exercises
- Threat intelligence integration (IOC feeds, TTP matching)
4. Vendor Risk Management
Extend security assessments to your software suppliers:
- Ask vendors about their build environment security
- Require SBOM (Software Bill of Materials) for critical software
- Monitor vendor security advisories proactively
- Have contingency plans for vendor compromises
5. Incident Response Readiness
Prepare for supply chain scenarios specifically:
- Playbooks for “trusted software acting maliciously”
- Communication templates for vendor compromise notifications
- Forensic capabilities for signed malware analysis
- Legal and regulatory response procedures
Broader Industry Implications
The DAEMON Tools attack, combined with eScan, Notepad++, and CPUID incidents in 2026, suggests we’re entering a new phase of supply chain warfare:
1. Industrialization of Supply Chain Attacks
What was once the domain of nation-states (SolarWinds, 2020) is now accessible to smaller groups. The pattern suggests:
- Reusable techniques and tooling
- Shared infrastructure and knowledge
- Lower barriers to entry
- Copycat attacks following successful precedents
2. The Small Vendor Targeting Strategy
DAEMON Tools, Notepad++, CPUID—these are not Microsoft or Google. They are:
- Smaller security teams
- Limited resources for hardening
- High user trust
- Wide distribution
This makes them ideal targets. Expect more attacks on “mid-tier” software vendors in 2026-2027.
3. The Signature Arms Race
As code signing becomes less meaningful as a security indicator, the industry must evolve:
- Reproducible builds (verify binary matches source)
- Build environment attestation (prove secure compilation)
- Continuous signing (re-sign after security checks)
- Behavioral verification (trust based on runtime behavior, not just signature)
4. The Endpoint Security Shift
Network perimeter defenses are increasingly ineffective against supply chain attacks. Security is shifting to:
- Endpoint detection and response (EDR)
- Behavioral analysis over signature matching
- Zero trust architectures
- Assumed-breach mindset
Timeline
- March 27, 2026: C2 domain
env-check.daemontools[.]ccregistered - April 8, 2026: Compromised installers begin distribution
- April 8 – May 6, 2026: Active infection period (versions 12.5.0.2421-2434)
- Early May 2026: Kaspersky discovers and reports the compromise
- May 6, 2026: Public disclosure and vendor notification
- Ongoing: Investigation and remediation efforts
Conclusion
The DAEMON Tools supply chain attack is a sobering reminder that in modern cybersecurity, trust is a vulnerability. The very mechanisms designed to assure software integrity—digital signatures, official distribution channels, established vendor reputations—can be weaponized when attackers compromise the source.
With several thousand infections across 100+ countries but advanced backdoors deployed to only a dozen carefully selected victims, this operation demonstrates both industrial-scale compromise capability and surgical precision in target selection. The attackers are patient, sophisticated, and adaptable—using multi-protocol C2, fileless execution, and process injection to evade detection.
For organizations, the lesson is clear: verify, monitor, and assume breach. No software is inherently trustworthy—only verifiably secure through continuous observation and defense-in-depth.
As we move through 2026’s supply chain attack wave, the question is not if your trusted software will be compromised, but when—and whether you’ll detect it before the attackers achieve their objectives.
In supply chain security, paranoia is a feature, not a bug.