PULSE NAME
Popular DAEMON Tools software compromised
WHITE AlienVault 2026-05-05 Modified: 2026-05-05
21
IOCs
MEDIUM VOLUME
Since April 8, 2026, installers of DAEMON Tools software have been compromised with malicious payloads distributed through the legitimate website. Versions 12.5.0.2421 to 12.5.0.2434 contain trojaned binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) signed with legitimate developer certificates. The attack has affected thousands of systems across over 100 countries, though advanced payloads were selectively deployed to approximately a dozen machines in government, scientific, manufacturing, and retail organizations. Initial infection establishes backdoor communications to typosquatted domains, followed by deployment of an information collector for system profiling. Targeted systems receive additional implants including a minimalistic backdoor and QUIC RAT. Chinese-language strings found in malicious components suggest a Chinese-speaking threat actor. The attack remains active at time of publication, demonstrating sophisticated supply chain compromise techniques comparable to the 2023 3CX ...
Indicators of Compromise (3 / 21 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 8c67ae3b4b8d30d13a8118701134d94e 2026-05-05
FileHash-MD5 a7f6308f3c7624a603e2242b19a0a8e7 2026-05-05
FileHash-MD5 f2bd550773af344661689e259ffb97ed 2026-05-05