CVE-2026-8398
Daemon Tools Lite Embedded Malicious Code Vulnerability
Description
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
Description as published by the source, in English.
Key facts
- Published
- 2026-05-15
- Last modified
- 2026-06-17
- Assigned by
- vulnerability@kaspersky.com
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:- Scored by
- vulnerability@kaspersky.com
- Probability of exploitation
-
1.5 %
higher than 71 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-05-27, with a remediation deadline of 2026-05-30 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Disc-soft | Daemon Tools | 12.5.1 | Affected |
| Microsoft | Windows | all versions listed | Not affected |
Weakness type
-
CWE-506: Embedded Malicious Code
The product contains code that appears to be malicious in nature.
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.
- T1001.002: Steganography
- T1027.003: Steganography
- T1027.004: Compile After Delivery
- T1027.009: Embedded Payloads
- T1195.001: Compromise Software Dependencies and Development Tools
- T1195.002: Compromise Software Supply Chain
- T1218.001: Compiled HTML File
- T1221: Template Injection
References
- https://blog.daemon-tools.cc/post/security-incident
- https://securelist.com/tr/daemon-tools-backdoor/119654/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8398
Related at Berigo
Articles
-
A fake CAPTCHA gets the user to open a tunnel into the network
Same product
2026-09-01
Microsoft has tracked the TerminalFix campaign, in which compromised websites show a fake Cloudflare CAPTCHA and ask visitors to paste a command into…
-
A Word macro was the way in at defence manufacturers and government bodies
Same product
2026-09-01
Insikt Group has mapped a campaign in which macro-enabled Word documents planted the HOOKEDGE backdoor at defence manufacturers, government bodies an…
-
Iran-linked group hides its backdoor inside a fake Windows DLL
Same product
2026-08-27
Group-IB has identified new malware samples and new infrastructure tied to the Iranian group Tortoiseshell. The findings include a reverse SSH tunnel…
-
Attackers are letting npm mirrors host their fake Cloudflare page
Same product
2026-08-27
OX Security has identified 24 malicious npm packages that all carry the same fake Cloudflare page. Installing them does no harm, but mirrors such as …
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.