The DAEMON Tools breach is a strong reminder that software supply-chain attacks are no longer limited to unknown or suspicious downloads. In this case, public reports state that the official DAEMON Tools Lite free installer was trojanized through unauthorized interference in the vendor’s build environment, and a malware-free version was later released by the developer.
This is especially concerning because users downloaded the compromised installer from the official website, and the trojanized binaries were reportedly digitally signed. The malware collected system information, established persistence, and, in some cases, deployed additional backdoor payloads capable of command execution, file download, and in-memory code execution.
Organizations must treat software downloads, updates, and developer/build environments as part of the security boundary. Protection should include restricting unauthorized software downloads, inspecting web traffic where applicable, monitoring unusual outbound connections, detecting suspicious command-and-control activity, and ensuring endpoint scans are performed after any known exposure.
This incident also reinforces the importance of downloading software only from trusted sources, verifying versions, maintaining application allowlists, and reviewing outbound communication from newly installed applications. The uncomfortable lesson is simple: even official software can become unsafe if the supply chain is compromised. Apparently “download from the official site” is now good advice, but no longer enough advice.
Disc Soft Limited, the maker of DAEMON Tools Lite, confirmed that the software had been trojanized in a supply chain attack and released a new, malware-free version. [...]
Source: DAEMON Tools devs confirm breach, release malware-free version via Bleeping Computer — published 06 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.