Critical supply chain attack (CVSS 9.8) affecting DAEMON Tools Lite. Trojanized binaries bypass signatures. Active exploitation reported in CISA KEV.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| daemon_tools | 12.5.1 | 12.5.1 | vulnerable |
| windows | - | - | unaffected |
Download the latest clean version of DAEMON Tools Lite directly from the official vendor website. Ensure you are using a version released after the May 2026 security incident and verify the installer's checksum against official vendor advisories.
Immediately uninstall compromised versions 12.5.0.2421 through 12.5.0.2434. While CPE data indicates version 12.5.1 may be affected, users should transition to the most recent version confirmed as clean by AVB Disc Soft to ensure all trojanized binaries are removed.
Isolate any workstations running the affected software from the production network until they have been reimaged or verified clean. Block outbound network traffic from DAEMON Tools processes at the host or network firewall level to prevent potential command-and-control communication.
Perform a retrospective hunt for the trojanized binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe) using known malicious hashes. Monitor for unusual child processes spawned by these services or unauthorized persistence mechanisms created during the period of infection.
Detection should focus on identifying the specific trojanized binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. Since these files carry legitimate digital signatures, signature-based antivirus may fail. Security teams should use EDR tools to monitor for unusual outbound network connections or unexpected shell executions originating from these processes. Check system logs for installation events between April 8 and May 5, 2026, and audit for unauthorized registry modifications or scheduled tasks.
Experience superior visibility and a simpler approach to cyber risk management