logo

Widespread DAEMON Tools Supply Chain Attack Enables Targeted Follow-on

ID: 596f9fdd-83ab-51d2-8e92-f1aa1a2244e1

STIX ID: report--596f9fdd-83ab-51d2-8e92-f1aa1a2244e1

Feed Name: Kudelski Security

Threat Score
85/100

Date Published: 2026-05-05

Date Updated: 2026-07-22

...
...

Kaspersky discovered a supply-chain compromise of official DAEMON Tools installers (versions 12.5.0.2421–12.5.0.2434) that were trojanized and still signed with valid certificates. Tampered binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) deploy an implant that checks in with env-check.daemontools.cc to receive commands and stage payloads (envchk.exe, cdg.exe/cdg.tmp, QUIC RAT). Thousands of infection attempts across 100+ countries were observed with selective follow-on targeting of retail, scientific, government and manufacturing entities in a few countries; mitigation advice includes isolating affected systems, blocking the C2 domain/IP, and monitoring execution of compromised binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.