CVE-2026-8398
KEV PoC largeTrojanized Installer Backdoor in DAEMON Tools Lite (Supply Chain Compromise)
CISA: Daemon Tools Lite Embedded Malicious Code Vulnerability
CVE-2026-8398 (CWE-506, embedded malicious code) is a supply chain compromise in which attackers gained access to AVB Disc Soft's build or distribution infrastructure and trojanized the official Windows installers of DAEMON Tools Lite versions 12.5.0.2421 through 12.5.0.2434, distributed from the legitimate site daemon-tools.cc between approximately April 8 and May 5, 2026. The flaw is triggered by installing or running one of these tampered builds, which shipped backdoored copies of DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe digitally signed with the vendor's legitimate code-signing certificate, allowing them to bypass signature-based detection. Once executed, the embedded backdoor gives attackers a trusted foothold and code execution on the affected Windows host, potentially enabling credential theft, further compromise, or ransomware follow-on activity (ransomware linkage currently unknown). Anyone who downloaded and installed DAEMON Tools Lite from the official site during the affected window is impacted; users with other or older builds are not part of this trojanized distribution. The issue was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-27, confirming exploitation in the wild, and a public technical write-up is available via Kaspersky's Securelist.
What to do: Identify hosts that installed DAEMON Tools Lite 12.5.0.2421–12.5.0.2434 from daemon-tools.cc during the affected window; remove/reinstall the software from a clean, current build obtained from the vendor and verify the signatures of DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. Because the trojanized binaries were validly signed, treat affected systems as potentially compromised and hunt for persistence, anomalous process activity, and C2 traffic associated with the backdoor. Federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product by the KEV deadline (listed 2026-05-27).
| disc-soft DAEMON Tools Lite | Windows versions 12.5.0.2421 through 12.5.0.2434 (installers distributed from daemon-tools.cc between approximately April 8, 2026 and May 5, 2026; trojanized bi |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
- Affected
- Daemon Daemon Tools Lite
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- disc-soft
- Products
- daemon tools
- Weakness
- CWE-506
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X