Knox CVE Database
/
CVE-2026-8398
Critical
9.3

CVE-2026-8398: Daemon Tools Lite Embedded Malicious Code Vulnerability

Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.

Added to the CISA KEV catalog:
May 27, 2026

Overview

DAEMON Tools Lite versions 12.5.0.2421 through 12.5.1, distributed from the official vendor site between April 8 and May 5, 2026, were trojanized through a compromise of AVB Disc Soft's build or distribution infrastructure. Three core binaries were replaced with backdoored versions, signed with the legitimate developer certificate. Any system running the affected installer received a persistent backdoor that beacons to an attacker-controlled server, accepts shell commands, and downloads secondary payloads including an information collector targeting system and network details.

Vulnerability details

Affected vendor
Daemon
Affected product
Daemon Tools Lite
Weakness type (CWE)
CWE-506

This is a supply chain compromise classified under CWE-506 (Embedded Malicious Code). Attackers modified three binaries inside official DAEMON Tools Lite installers: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. Because the files retained valid AVB Disc Soft code-signing certificates, signature-based defenses did not flag them. The malicious code was injected into the CRT startup path, so the backdoor activates automatically each time any of these binaries launches, which occurs at system startup. No user interaction beyond installation is required.


Once active, the backdoor runs in a dedicated thread and sends HTTP GET requests to env-check.daemontools[.]cc, a typosquatting domain registered roughly one week before the attack began, passing the victim's hostname as a query parameter. The C2 server responds with shell commands executed via cmd.exe, which download and run additional executables from a secondary server. Kaspersky observed an information collector deployed as a first-stage payload, harvesting MAC address, hostname, DNS domain, running processes, installed software, and system locale. Further-stage payloads were deployed selectively to victims in retail, scientific, government, and manufacturing organizations, indicating a targeted operation.

Severity and impact

9.3
Critical
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor for outbound HTTP GET requests from DTHelper.exe, DiscSoftBusServiceLite.exe, or DTShellHlp.exe to env-check.daemontools[.]cc or any domain other than daemon-tools.cc; these processes have no legitimate reason to initiate network connections.
  • Look for cmd.exe or powershell.exe processes spawned as children of DTHelper.exe, DiscSoftBusServiceLite.exe, or DTShellHlp.exe, particularly with arguments referencing DownloadFile, Windows\Temp executables, or the IP 38.180.107.76.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
May 30, 2026

Additional hardening

  • Upgrade to DAEMON Tools Lite 12.6.0.2445 or later; the vendor confirmed this release does not contain the malicious binaries and was verified by Kaspersky.
  • Uninstall any version between 12.5.0.2421 and 12.5.1 immediately and run a full endpoint scan before reinstalling; the backdoor activates at startup, so the system should be treated as compromised until cleared.
  • Block outbound connections to env-check.daemontools[.]cc and the IP address 38.180.107.76 at the network perimeter to interrupt C2 communication on already-infected hosts.
  • Audit process-creation logs and parent-child process trees on hosts where the affected versions were installed, focusing on cmd.exe or powershell.exe children of the three named binaries, to identify whether further-stage payloads were delivered.

Key dates

Published (NVD)
May 15, 2026
Added to CISA KEV
May 27, 2026
Remediation deadline
May 30, 2026
Last updated
June 17, 2026

References

Frequently asked questions

Does CVE-2026-8398 affect my FedRAMP authorization?

If Daemon Tools Lite runs inside your authorization boundary, CVE-2026-8398 affects your Federal Risk and Authorization Management Program (FedRAMP) authorization directly. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, and its May 30, 2026 remediation deadline has already passed. An unpatched KEV inside your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. At this point, you remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-8398?

Knox does not patch Daemon Tools Lite on your behalf. Under the FedRAMP shared-responsibility model, that remediation is yours to execute. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. Applying the patch is your responsibility. Managing your compliance posture while you do it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-8398. Exposure surfaces during ongoing monitoring rather than waiting until an assessor flags it at review time, giving you a shorter window between disclosure and awareness.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-8398's remediation deadline of May 30, 2026 has passed. What happens now?

If CVE-2026-8398 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your agency. Closing the finding out now and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid footing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.