Official Windows installers for DAEMON Tools were compromised in a supply chain attack, with malicious versions distributed from the vendor’s legitimate website beginning on April 8. Kaspersky said the trojanized installers affected DAEMON Tools Lite versions 12.5.0.2421 through 12.5.0.2434, were signed with valid AVB Disc Soft certificates, and implanted a staged backdoor that contacted the typosquatted command-and-control domain env-check.daemontools[.]cc. TechCrunch reported that an independently downloaded installer also appeared to contain the backdoor when scanned, while Disc Soft said it was investigating and taking remediation steps.
Researchers observed thousands of infection attempts across more than 100 countries, but the attackers appear to have selectively escalated only a small number of victims in Russia, Belarus, and Thailand. Follow-on activity targeted organizations in the government, scientific, manufacturing, and retail sectors and included additional payloads such as an information stealer, an in-memory backdoor using RC4, and a more advanced QUIC RAT. Kaspersky said Chinese-language artifacts in the malware suggest a Chinese-speaking threat actor may be involved, though attribution remains unconfirmed, and urged defenders to hunt for related hashes, suspicious DAEMON Tools process activity, and communications with env-check.daemontools[.]cc and 38.180.107[.]76.

Trace attribution and downstream blast radius.
8 events from the most recent confirmed update back to the earliest known activity.
A Google Cloud Threat Intelligence blog attributed the early 2026 DAEMON Tools installer compromise to UNC6863. The post said the campaign deployed SLICKDEMON, BADFALL, and QUIC RAT against targets in multiple countries, adding a named actor attribution beyond earlier reporting.
After acknowledging the supply chain compromise, AVB Disc Soft released clean DAEMON Tools version 12.6.0.2445 to replace the trojanized installer range 12.5.0.2421 through 12.5.0.2434. The release marked the vendor's first specific remediation step beyond its initial investigation statement.
On publication day, Disc Soft said it was aware of the report, was investigating the issue, and was taking remediation steps, but had not yet confirmed all of the reported details. TechCrunch also independently downloaded the installer and observed signs of the backdoor via VirusTotal scanning.
In early May 2026, Kaspersky identified that official DAEMON Tools installers had been trojanized and linked the campaign to thousands of infection attempts across more than 100 countries. Malware analysis found Chinese-language artifacts, leading Kaspersky to suspect a Chinese-speaking threat actor, though attribution was not confirmed.
After initial infections, the attackers selectively deployed additional malware to a small subset of victims in Russia, Belarus, and Thailand, affecting organizations in government, scientific, manufacturing, and retail sectors. Later-stage payloads included an information stealer, an in-memory RC4-enabled backdoor, and QUIC RAT.
Kaspersky said the supply chain attack began on 2026-04-08, when official Windows installers for DAEMON Tools Lite started being distributed from the vendor's legitimate website with a malicious backdoor embedded. The affected installer range included versions 12.5.0.2421 through 12.5.0.2434 and the files were signed with valid AVB Disc Soft certificates.
Notepad++ published an incident update stating it had been hijacked by state-sponsored hackers. This is a separate software supply-chain/security incident from the DAEMON Tools compromise already captured in the timeline.
The FBI issued a public notice stating that North Korean TraderTraitor actors were responsible for the $1.5 billion Bybit hack and subsequent laundering activity. The bureau urged exchanges, RPC node operators, bridges, DeFi services, and blockchain analytics firms to block transactions tied to listed Ethereum addresses associated with the stolen assets.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 88 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
14 references tracked. Mallory keeps watching after this page renders.
cloud.google.com
Open sourcecvefeed.io
Open sourceblog.polyswarm.io
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourcenotepad-plus-plus.org
Open sourcefbi.gov
Open sourcesygnia.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.