DAEMON Tools Lite signed-build trojanisation (12.5.0.2421-12.5.0.2434) via Disc Soft Limited build infrastructure compromise — six-week distribution window 2026-04-08 → 2026-05-05
cve · CVE-2026-8398
Coverage timeline
1
first 2026-05-28 → last 2026-05-28
Briefs
1
1 distinct
Sources cited
27
22 hosts
Sections touched
1
deep_dive
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-05-28CTI Daily Brief — 2026-05-28
Where this entity is cited
- deep_dive1
Source distribution
- attack.mitre.org3 (11%)
- github.com2 (7%)
- helpnetsecurity.com2 (7%)
- kaspersky.com2 (7%)
- bleepingcomputer.com1 (4%)
- blog.daemon-tools.cc1 (4%)
- blog.talosintelligence.com1 (4%)
- ccb.belgium.be1 (4%)
- other14 (52%)
External references
All cited sources (27)
- blog.daemon-tools.ccprimaryinlineDisc Softhttps://blog.daemon-tools.cc/post/security-incident
- attack.mitre.orginlineT1068 Exploitation for Privilege Escalationhttps://attack.mitre.org/techniques/T1068/
- attack.mitre.orginlineT1543.002 Create or Modify System Process: Systemd Servicehttps://attack.mitre.org/techniques/T1543/002/
- attack.mitre.orginlineT1552.004 Unsecured Credentials: Private Keyshttps://attack.mitre.org/techniques/T1552/004/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-06https://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/
- blog.talosintelligence.cominlineCisco Talos, 2026-05-14https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/
- ccb.belgium.beinlineCCB Belgium, 2026-05-20https://ccb.belgium.be/advisories/warning-nlnet-labs-has-addressed-multiple-vulnerabilities-unbound-dns-resolver-could
- cisa.govinlineCISA KEV, 2026-05-27https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- github.cominlineGitHub Security Advisory GHSA-c9j4-9m59-847whttps://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w
- github.cominlineTanStack Router GHSA-g7cv-rxg3-hmpxhttps://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx
- helpnetsecurity.cominlineHelp Net Security, 2026-05-21https://www.helpnetsecurity.com/2026/05/21/github-grafana-breach-root-cause-nx-console/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-06https://www.helpnetsecurity.com/2026/05/06/daemon-tools-compromised-backdoors-supply-chain-attack/
- kaspersky.cominlineKaspersky, 2026-05-05https://www.kaspersky.com/blog/daemon-tools-supply-chain-attack/55691/
- kaspersky.cominlineKaspersky press release, 2026-05-05https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware
- kb.isc.orginlineISC, 2026-05-20https://kb.isc.org/docs/cve-2026-5946
- lumen.cominlineLumen Black Lotus Labs, 2026-05-21https://www.lumen.com/blog/en-us/introducing-showboat-a-new-malware-family-taunts-defenses-and-targets-international-telecom-firms
- malwarebytes.cominlineMalwarebytes — Shub Stealer earlier wave, 2026-03https://www.malwarebytes.com/blog/threat-intel/2026/03/fake-cleanmymac-site-installs-shub-stealer-and-backdoors-crypto-wallets
- microsoft.cominlineMicrosoft Security Blog, 2026-05-06https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/
- nlnetlabs.nlinlineNLnet Labs, 2026-05-20https://nlnetlabs.nl/downloads/unbound/CVE-2026-33278.txt
- nx.devinlineNx postmortem, 2026-05-19https://nx.dev/blog/nx-console-v18-95-0-postmortem
- pwc.cominlinePwC Threat Intelligence, 2026-05-21https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/red-lamassu-open-season.html
- rapid7.cominlineRapid7, 2026-05-14https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/
- sec.cloudapps.cisco.cominlineCisco PSIRT advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW
- securelist.cominlineKaspersky Securelist, 2026-05-06https://securelist.com/tr/daemon-tools-backdoor/119654/
- socket.devinlineSocket, 2026-05-22https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos
- thehackernews.cominlineThe Hacker News, 2026-05-23https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html
- therecord.mediainlineThe Record, 2026-05-06https://therecord.media/hackers-compromise-daemon-tools-global-supply-chain-attack
Items in briefs about DAEMON Tools Lite signed-build trojanisation (12.5.0.2421-12.5.0.2434) via Disc Soft Limited build infrastructure compromise — six-week distribution window 2026-04-08 → 2026-05-05
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.