CVE-2026-8398
Description
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
Summary dbcve.org
This is a supply chain attack where threat actors compromised AVB Disc Soft's build or distribution infrastructure and trojanized three binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) in DAEMON Tools Lite versions 12.5.0.2421-12.5.0.2434. The malicious installers were digitally signed with the vendor's legitimate code-signing certificate, enabling them to bypass signature-based security controls and appear trustworthy to users and security tools.
Mitigation
Users who installed DAEMON Tools Lite between April 8, 2026 and May 5, 2026 should immediately uninstall the affected version, perform a full malware scan, and reinstall version 12.5.0.2435 or later from the official website. Organizations should audit affected endpoints for indicators of compromise and consider rebuilding systems if infection is suspected.