Executive brief
DAEMON Tools Lite, a popular software for mounting disk images, was the victim of a supply chain attack where its official installation packages were compromised with malicious code. Attackers gained access to the vendor's distribution infrastructure to include a backdoor in the software, which was then distributed to thousands of users globally. This compromise allows attackers to remotely control infected computers, steal sensitive information, and deploy additional malware, potentially leading to full system takeover and data theft.
Technical details
A supply chain attack (CWE-506) targeted the build and distribution infrastructure of AVB Disc Soft, resulting in the trojanization of three core binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These binaries were digitally signed with the vendor's legitimate code-signing certificate, allowing them to bypass standard security checks. Upon execution, the embedded backdoor initiates a thread that communicates with a typosquatted C2 domain (env-check.daemontools[.]cc) via HTTPS GET requests. The attackers can then execute arbitrary shell commands via cmd.exe and PowerShell to deploy further payloads, including information collectors and remote access trojans (RATs). The vulnerability was addressed in version 12.6.0.2445.
Affected products
- AVB Disc Soft (Disc Soft Limited) DAEMON Tools Lite 12.5.0.2421 through 12.5.0.2434
CVE identifiers
- CVE-2026-48027
- CVE-2026-45321
- CVE-2026-8398
Timeline
- 2026-04-08: exploited: Earliest date compromised installers were distributed.
- 2026-05-05: patched: Vendor released version 12.6 to address the incident.
- 2026-05-05: disclosed: Kaspersky published initial research on the supply chain attack.
- 2026-05-15: advisory: CVE-2026-8398 published to NVD.
- 2026-05-27: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog.