Vulnerability Intelligence Report
Daemon Tools Lite Embedded Malicious Code Vulnerability
CVE-2026-8398
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.3
CRITICAL
EPSS Probability:1.44%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-506 ↗CWE-506: Embedded Malicious Code
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| AVB Disc Soft | DAEMON Tools Lite | 12.5.0.2421 < 2.6.0.* (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Kaspersky · Vendor · Russia |
| Reserved | 2026-05-12T13:20:16 |
| Published | 2026-05-15T07:30:29 |
| Last Updated | 2026-05-28T03:55:20 |
Community Chatter & Buzz