Vulnerability record · CVE-2026-8398 · published 15 May 2026
CVE-2026-8398: DAEMON Tools Lite installers trojanized via supply chain compromise
Disc Soft · Daemon Tools
Attackers breached AVB Disc Soft's build or distribution infrastructure and trojanized three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) shipped in DAEMON Tools Lite Windows installers 12.5.0.2421 through 12.5.0.2434 from daemon-tools.cc between roughly April 8 and May 5, 2026. Because the files carry the legitimate vendor code-signing certificate, signature-based trust and detection are bypassed. This is a confirmed supply chain compromise of a widely distributed consumer application, not a coding bug in the product itself.
Description
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityA confirmed, signed supply chain compromise of a widely distributed installer that is listed in CISA KEV with a CVSS 4.0 score of 9.3 and no authentication barrier.
What it is
Attackers breached AVB Disc Soft's build or distribution infrastructure and trojanized three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) shipped in DAEMON Tools Lite Windows installers 12.5.0.2421 through 12.5.0.2434 from daemon-tools.cc between roughly April 8 and May 5, 2026. Because the files carry the legitimate vendor code-signing certificate, signature-based trust and detection are bypassed. This is a confirmed supply chain compromise of a widely distributed consumer application, not a coding bug in the product itself.
Impact
An attacker gains code execution on any host that installed an affected package, with the malicious binaries running under the vendor's legitimate signature. The record does not state the specific payload or post-exploitation behavior beyond the backdoor reference.
Attack surface
Reached by downloading and installing the affected DAEMON Tools Lite package from the legitimate vendor site; no authentication or special user interaction beyond running the installer is required, consistent with the CVSS 4.0 vector AV:N/PR:N/UI:N. The compromise is in the distribution channel, not in a remotely reachable service.
Exploitation
Listed in CISA KEV (added 2026-05-27, due 2026-05-30), indicating known exploitation in the wild; EPSS 30-day probability is 0.01456 (72nd percentile), and a third-party reference is tagged Exploit. No ransomware campaign use is documented.
What to do
- Remove or reinstall DAEMON Tools Lite using a package confirmed clean by the vendor; do not trust existing installs of versions 12.5.0.2421 through 12.5.0.2434.
- Follow the vendor security incident advisory and CISA KEV required action, including BOD 22-01 guidance for cloud services or discontinuing the product if mitigations are unavailable.
- Hunt for and block the three trojanized binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) by hash where available, and treat their presence as compromise.
- Do not rely on code-signing validation alone for this vendor's packages; verify hashes against vendor-published clean values before deployment.
- Rotate credentials and review systems that ran affected installers for signs of backdoor persistence or lateral movement.
Detection
- Search endpoint telemetry for execution of DTHelper.exe, DiscSoftBusServiceLite.exe, or DTShellHlp.exe outside expected install paths or after the incident window.
- Alert on DAEMON Tools Lite installer files matching versions 12.5.0.2421 to 12.5.0.2434 or downloaded from daemon-tools.cc between April 8 and May 5, 2026.
- Monitor for outbound network connections or child processes spawned by the three named binaries, which are not expected to initiate such activity.
- Correlate file creation of the signed binaries with subsequent persistence or credential-access behavior on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-8398 to the Known Exploited Vulnerabilities catalog on 27 May 2026 as "Daemon Tools Lite Embedded Malicious Code Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 30 May 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.daemon-tools.cc/post/security-incident | Vendor Advisory |
| https://securelist.com/tr/daemon-tools-backdoor/119654/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8398 | US Government Resource |
Track CVE-2026-8398 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-8398), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.